Breaking: VMware vCenter Under Active Attack — 361 Victims Across 47 Countries — 13 August 2026
VMware vCenter Under Active Attack — 361 Victims Across 47 Countries
A critical VMware vCenter vulnerability disclosed just two weeks ago is being exploited at speed and scale. CVE-2026-59310, a directory-traversal flaw in the vCenter Syslog server carrying a CVSS score of 9.8, allows an attacker with network access to execute arbitrary code on the appliance. Broadcom disclosed the vulnerability on July 29 and released patches through VMSA-2026-0006.1 for vCenter 9.1, 9.0, and 8.0. There is no workaround.
By August 3, five days after disclosure, attacker-controlled infrastructure was already receiving connections from compromised systems. The following day brought another 151 victim IPs. By August 5, 343 of the 361 identified victim IPs had been catalogued. The speed is consistent with automated exploitation of internet-facing vCenter instances, and the geographic spread (47 countries, with Germany, the United States, Turkey, Iran, and France most affected) confirms that this is not a targeted campaign but an opportunistic scramble for any unpatched vCenter reachable on the open internet.
After gaining access, the threat actor deploys reverse_ssh, an open-source SSH-based reverse-shell framework. This establishes persistent outbound connect-back channels from the compromised vCenter, bypassing perimeter controls and surviving reboots. The tool handles port forwarding, file transfers, and remote shell management, giving the attacker a durable foothold in the virtualisation management plane. From vCenter, an adversary has full control over the virtual infrastructure: VM creation, deletion, snapshot extraction, credential harvesting from guest OS configurations. It is the keys to the kingdom for any organisation running VMware.
The research comes from QUIRSO GmbH's Threat Research team, which has been tracking the campaign and correlating victim IPs with their Honeypot infrastructure. They emphasise that the 361 figure represents IP addresses, not organisations, and a single enterprise could account for multiple IPs. But the direction is clear: the count is growing, and many of these IPs belong to data centre and hosting providers whose compromise cascades downstream to their customers.
Germany's position as the most affected country is significant for European security teams. vCenter is the management control plane for the majority of enterprise virtualisation estates. An unpatched internet-facing vCenter is now a near-guaranteed compromise.
Patch immediately. If vCenter instances cannot be patched, remove them from internet exposure entirely, isolate the management network, and audit outbound connections from August 3 onward. Search for unauthorized reverse_ssh binaries, unexpected SSH tunnels, and any unexplained outbound connections from vCenter appliances. Treat any unpatched internet-facing vCenter as potentially compromised until forensic review proves otherwise. Broadcom's advisory covers vCenter, VMware Cloud Foundation, vSphere Foundation, and Telco Cloud products; check all of them.

