# VMware vCenter critical vulnerability exploitation

> Live situation record from CLSTR: https://clstr.news/situations/vmware-vcenter-critical-vulnerability-exploitation
> Updated: 2026-08-12T10:56:17.000Z. Sources: 11. Developments: 2.

A critical directory traversal vulnerability in the VMware vCenter Syslog service, identified as CVE-2026-59310, is undergoing active exploitation. The flaw, which carries a CVSS score of 9.8, was identified shortly after Broadcom issued an advisory. 

Forensic analysis indicates that attackers began connecting compromised systems to their infrastructure on August 3. The exploitation was rapid, with approximately 95 percent of identified victim addresses appearing within a 72-hour window. Attackers have been observed using a tool named ‘reverse_ssh’ to bypass traditional firewall rules via outbound traffic and employing cron entries to maintain persistence. Broadcom has stated that applying the official update is the only supported method to resolve the issue, as no workaround exists for the affected vCenter branches.

## Claims

- CVE-2026-20349 is a critical zero-day vulnerability affecting Cisco Secure Firewall ASA and FTD software. (corroborated by 4 sources)
- The vulnerability has a CVSS score of 8.6. (corroborated by 3 sources)
- Unauthenticated remote attackers can trigger a complete system crash via malformed HTTP requests. (corroborated by 3 sources)
- CISA added the flaw to its Known Exploited Vulnerabilities catalog. (corroborated by 2 sources)

## Timeline

### 2026-08-12: Cisco warns of critical zero-day vulnerability in Secure Firewall ASA and FTD

Cisco is addressing a critical zero-day vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD software. The flaw allows unauthenticated remote attackers to cause a Denial of Service via system re-re

9 sources. https://clstr.news/cluster/cisco-discloses-high-severity-vpn-vulnerability-being-exploited-in-the-wild

### 2026-08-12: VMware vCenter faces active exploitation of critical vulnerability

A critical 9.8 CVSS vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited, while Broadcom's restructuring of the VMware partner program continues to shift the market landscape.

2 sources. https://clstr.news/cluster/vmware-vcenter-faces-active-exploitation-of-critical-vulnerability

---
Cite as: VMware vCenter critical vulnerability exploitation. CLSTR, https://clstr.news/situations/vmware-vcenter-critical-vulnerability-exploitation
