< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 11 sources · 1 days · First seen · Last updated

VMware vCenter critical vulnerability exploitation

Overview

A critical directory traversal vulnerability in the VMware vCenter Syslog service, identified as CVE-2026-59310, is undergoing active exploitation. The flaw, which carries a CVSS score of 9.8, was identified shortly after Broadcom issued an advisory.

Forensic analysis indicates that attackers began connecting compromised systems to their infrastructure on August 3. The exploitation was rapid, with approximately 95 percent of identified victim addresses appearing within a 72-hour window. Attackers have been observed using a tool named ‘reverse_ssh’ to bypass traditional firewall rules via outbound traffic and employing cron entries to maintain persistence. Broadcom has stated that applying the official update is the only supported method to resolve the issue, as no workaround exists for the affected vCenter branches.

Entities

Fortinet · Cisco · CISA · Quirso · vCenter

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 9 sources
    Cisco warns of critical zero-day vulnerability in Secure Firewall ASA and FTD

    Cisco is addressing a critical zero-day vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD software. The flaw allows unauthenticated remote attackers to cause a Denial of Service via system re-re

  2. 1 day ago

    [TECHNOLOGY] 2 sources
    VMware vCenter faces active exploitation of critical vulnerability

    A critical 9.8 CVSS vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited, while Broadcom's restructuring of the VMware partner program continues to shift the market landscape.

Sources

bgr.com · blogspan.net · cybersecuritynews.com · dev.to · flagthis.com · hothardware.com · it-boltwise.de · itiko.de · profesionalreview.com · security-insider.de · socprime.com