VMware vCenter: CVE-2026-59310 exploited
Telconet and Shadowserver confirmed active exploitation of CVE-2026-59310 in vCenter. Broadcom has issued patches and there is no workaround.
Advanced threat actors are actively exploiting CVE-2026-59310 in VMware vCenter, according to Telconet CSIRT, which reported unauthenticated remote code execution in the Syslog component. Shadowserver, meanwhile, warned that identified systems should be treated as fully compromised because reported cases involved deployment of reverse_ssh for persistence.
Telconet CSIRT said advanced threat actors are actively exploiting CVE-2026-59310 in VMware vCenter, a flaw rated CVSS 9.8. The team described it as a directory traversal issue in VMware vCenter Syslog Server that can lead to unauthenticated remote code execution in the Syslog component.
What is the impact of active exploitation of CVE-2026-59310?
According to the same bulletin, the impact can reach system-level privileges and enable persistence through reverse_ssh. That combination makes the flaw especially sensitive in Internet-facing environments, where active exploitation has already been observed.
What did Broadcom publish for CVE-2026-59310?
Hispasec reported that Broadcom released fixes for CVE-2026-59310 in advisory VMSA-2026-0006.1. It also said there is no workaround, so the recommended mitigation is to apply the vCenter updates.
Daily.dev also reported that Broadcom issued a patch on 2026-07-29 and that the fixed versions for vCenter are 9.1.0.0300, 9.0.2.0100, and 8.0 U3k/U2f.
What did Shadowserver and QUIRSO say about the victims?
Shadowserver published a special victim report on CVE-2026-59310 on 2026-08-12 based on identifications from QUIRSO. The foundation said the reported systems should be considered fully compromised because reverse_ssh was deployed in every reported case.
A secondary report attributed to DFIR firm QUIRSO the figure of 361 compromised IPs across 47 countries as of 2026-08-07, although that number was presented as unofficial and unconfirmed. Telconet's bulletin provides the closest regional reference in the available material, but there is no broad independent attribution for Latin America in the sources reviewed.
Sources
- Amenaza crítica a VMware vCenter (CVE-2026-59310)csirt.telconet.net· CSIRT Telconet
- Atacantes explotan un fallo crítico en VMware vCenter para instalar acceso remoto persistenteunaaldia.hispasec.com· una al día / Hispasec
- Critical VMware vCenter RCE flaw exploited for reverse SSH accessdaily.dev· daily.dev
- Hackers Actively Exploiting VMware vCenter Systems to Gain and Maintain Remote Accesscybersecuritynews.com· CybersecurityNews
- CRITICAL: VMware vCenter CVE-2026-59310 Exploitation Victim Special Reportshadowserver.org· Shadowserver Foundation



