vCenter Exploits Left Reverse SSH Footholds Behind
QUIRSO said attackers have been exploiting Broadcom VMware vCenter CVE-2026-59310, a critical directory-traversal flaw, to run code and keep access on compromised hosts. The firm traced the campaign to 361 unique victim IP addresses in 47 countries, with first contact seen on August 3.
The chain starts with path traversal in vCenter, then adds a malicious cron job that launches reverse_ssh on a timer. That turns the appliance into an outbound relay to attacker-controlled infrastructure, so fixing the vulnerability alone may leave a live foothold on the management host.
For operators of vCenter and similar management-plane systems, the exposure is the controller itself: if it can reach many internal systems, a compromise there can stay useful even after the initial bug is patched.