VMware vCenter CVE-2026-59310 Actively Exploited for Unauthenticated Remote Access
A critical vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, is being actively exploited just five days after a patch was released. Attackers are targeting internet-exposed vCenter Syslog Servers using a directory traversal flaw to achieve unauthenticated remote code execution without any credentials. Once inside, they deploy a persistent cron job and an open-source reverse_ssh client to establish an outbound SSH connection back to an attacker-controlled command-and-control server, effectively bypassing inbound firewall rules. Broadcom has issued no workaround, making immediate patching the only remediation option. While vCenter serves as the central management plane for ESXi and virtual machines, no public evidence currently confirms that attackers have successfully leveraged this access to impact managed infrastructure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in