started · updated
VMware vCenter faces active exploitation of critical vulnerability
A critical directory traversal vulnerability in the VMware vCenter Syslog service, identified as CVE-2026-59310, is being actively exploited. The flaw carries a CVSS score of 9.8. Forensic analysis by the German firm Quirso revealed that attackers began connecting compromised systems to their infrastructure on August 3, just five days after Broadcom issued an advisory. The exploitation wave was rapid, with approximately 95 percent of the 361 identified victim addresses appearing within 72 hours.
Attackers utilized a tool called reverse_ssh to establish connections that bypass traditional firewall rules by initiating outbound traffic. To maintain persistence, they employed cron entries. Broadcom has stated that applying the official update is the only supported method to resolve the issue, as no workaround is available for the affected vCenter branches.
Separately, the restructuring of the VMware partner program by Broadcom has significantly altered the market landscape. The new VMware Advantage Partner Program focuses on a smaller group of highly qualified partners, leaving many previous partners outside the official network. This shift has created challenges for companies seeking reliable support for their virtualization and private cloud infrastructures.