Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 11 sources · 1 days · First seen · Last updated
VMware vCenter critical vulnerability exploitation
Overview
A critical directory traversal vulnerability in the VMware vCenter Syslog service, identified as CVE-2026-59310, is undergoing active exploitation. The flaw, which carries a CVSS score of 9.8, was identified shortly after Broadcom issued an advisory.
Forensic analysis indicates that attackers began connecting compromised systems to their infrastructure on August 3. The exploitation was rapid, with approximately 95 percent of identified victim addresses appearing within a 72-hour window. Attackers have been observed using a tool named ‘reverse_ssh’ to bypass traditional firewall rules via outbound traffic and employing cron entries to maintain persistence. Broadcom has stated that applying the official update is the only supported method to resolve the issue, as no workaround exists for the affected vCenter branches.
Entities
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 4 SOURCES] CVE-2026-20349 is a critical zero-day vulnerability affecting Cisco Secure Firewall ASA and FTD software. flagthis.com · socprime.com · www.security-insider.de · dev.to
- [● 3 SOURCES] The vulnerability has a CVSS score of 8.6. flagthis.com · socprime.com · www.security-insider.de
- [● 3 SOURCES] Unauthenticated remote attackers can trigger a complete system crash via malformed HTTP requests. flagthis.com · socprime.com · www.security-insider.de
- [● 2 SOURCES] CISA added the flaw to its Known Exploited Vulnerabilities catalog. socprime.com · www.security-insider.de
Timeline
-
1 day ago
[TECHNOLOGY] 9 sourcesCisco warns of critical zero-day vulnerability in Secure Firewall ASA and FTDCisco is addressing a critical zero-day vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD software. The flaw allows unauthenticated remote attackers to cause a Denial of Service via system re-re
-
1 day ago
[TECHNOLOGY] 2 sourcesVMware vCenter faces active exploitation of critical vulnerabilityA critical 9.8 CVSS vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited, while Broadcom's restructuring of the VMware partner program continues to shift the market landscape.
Sources
bgr.com · blogspan.net · cybersecuritynews.com · dev.to · flagthis.com · hothardware.com · it-boltwise.de · itiko.de · profesionalreview.com · security-insider.de · socprime.com