Home / Aug 14, 2026 / Story
0
#4 BleepingComputer general August 13, 2026 at 16:40 UTC

Critical VMware vCenter RCE flaw exploited for reverse SSH access

By Bill Toulas

AI Summary

CVE-2026-59310, a critical directory traversal RCE flaw in VMware vCenter's Syslog Server component, is being actively exploited in a global campaign to deploy a reverse SSH tool for persistent remote access. Patching alone may be insufficient to fully remediate compromised systems, as attackers have already established persistence via the reverse shell mechanism. VMware administrators should audit for indicators of compromise in addition to applying available patches.

Relevance score: 88.0/100

# More from August 14