<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w" -->

---
title: Critical VMware vCenter RCE flaw exploited for reverse...
description: A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter&#x27;s Syslog Server, patched by Broadcom on July 29, is being actively exploited to...
canonical: https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical VMware vCenter RCE flaw exploited for reverse SSH access | daily.dev
og:description: A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter&#x27;s Syslog Server, patched by Broadcom on July 29, is being actively exploited to...
og:url: https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w
og:image: https://api.daily.dev/og/posts/XLVhSeH6w.png
og:image:alt: Critical VMware vCenter RCE flaw exploited for reverse SSH access
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical VMware vCenter RCE flaw exploited for reverse SSH access

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter's Syslog Server, patched by Broadcom on July 29, is being actively exploited to gain unauthenticated remote code execution. DFIR firm QUIRSO reports 361 compromised IP addresses across 47 countries as of August 7, with attackers deploying the open-source reverse_ssh tool for persistent, firewall-evading command-and-control access. Broadcom offers no workarounds; admins must update to vCenter 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access>

## Questions this post answers

### What is CVE-2026-59310 and which VMware vCenter versions are affected?

CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog Server that lets an unauthenticated attacker with network access execute arbitrary code. Broadcom disclosed it on July 29 with no workarounds available. Fixed versions are vCenter 9.1.0.0300, vCenter 9.0.2.0100, and vCenter 8.0 U3k or 8.0 U2f depending on the branch.

_daily.dev helps admins patching vCenter track critical CVEs like this before attackers strike._

### How are attackers exploiting the VMware vCenter Syslog Server vulnerability?

Attackers exploit the flaw to gain code execution on vulnerable vCenter systems, then deploy the open-source reverse_ssh framework to establish an outbound command-and-control channel for persistence and remote access, which also helps bypass firewalls. Digital forensics firm QUIRSO observed exploitation starting August 3, just five days after disclosure, reaching 361 victim IPs across 47 countries by August 7.

_security teams tracking active vCenter exploitation can follow incident details like these on daily.dev._

### Is there a way to detect reverse_ssh backdoors deployed via the vCenter vulnerability?

A generic YARA rule released by QUIRSO can detect reverse_ssh client binaries, though legitimate uses of the open-source tool will also trigger the alert, so results require manual verification. QUIRSO has withheld specific indicators of compromise pending coordination with law enforcement and plans a follow-up report on the attacker's infrastructure and techniques.

_responders hunting for reverse_ssh backdoors can keep up with detection guidance via daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#ssh](https://daily.dev/tags/ssh)

[View this post on daily.dev](https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical VMware vCenter RCE flaw exploited for reverse SSH access","url":"https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w"},"datePublished":"2026-08-13T16:44:38.675Z","dateModified":"2026-09-14T07:30:43.333Z","description":"A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter's Syslog Server, patched by Broadcom on July 29, is being actively exploited to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f664909029aab5ea56ff500c442a5b84?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f664909029aab5ea56ff500c442a5b84?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ssh","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Critical VMware vCenter RCE flaw exploited for reverse SSH access"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access-xlvhseh6w#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-59310 and which VMware vCenter versions are affected?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog Server that lets an unauthenticated attacker with network access execute arbitrary code. Broadcom disclosed it on July 29 with no workarounds available. Fixed versions are vCenter 9.1.0.0300, vCenter 9.0.2.0100, and vCenter 8.0 U3k or 8.0 U2f depending on the branch. daily.dev helps admins patching vCenter track critical CVEs like this before attackers strike."}},{"@type":"Question","name":"How are attackers exploiting the VMware vCenter Syslog Server vulnerability?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploit the flaw to gain code execution on vulnerable vCenter systems, then deploy the open-source reverse_ssh framework to establish an outbound command-and-control channel for persistence and remote access, which also helps bypass firewalls. Digital forensics firm QUIRSO observed exploitation starting August 3, just five days after disclosure, reaching 361 victim IPs across 47 countries by August 7. security teams tracking active vCenter exploitation can follow incident details like these on daily.dev."}},{"@type":"Question","name":"Is there a way to detect reverse_ssh backdoors deployed via the vCenter vulnerability?","acceptedAnswer":{"@type":"Answer","text":"A generic YARA rule released by QUIRSO can detect reverse_ssh client binaries, though legitimate uses of the open-source tool will also trigger the alert, so results require manual verification. QUIRSO has withheld specific indicators of compromise pending coordination with law enforcement and plans a follow-up report on the attacker's infrastructure and techniques. responders hunting for reverse_ssh backdoors can keep up with detection guidance via daily.dev."}}]}
```

