Attackers are actively exploiting a critical VMware vCenter flaw disclosed late last month, using it to plant persistent reverse SSH access. German security firm QUIRSO counted as many as 361 unique victim IP addresses across 47 countries, concentrated in Germany, the US, Turkey, Iran, and France.
Broadcom patched the underlying issue, CVE-2026-59310 (CVSS 9.8), at the end of July. It is a directory traversal in the vCenter Server, and anyone with network reach can exploit it to run arbitrary code.
QUIRSO’s team found the activity during an incident response engagement. The chain QUIRSO observed fit the flaw’s path traversal pattern. The persistence step used reverse_ssh, an open-source tunneling tool that connects out to servers run by the attackers. It arrived through a cron job planted on the host. Outbound connections of this kind sail past defenses that only scrutinize inbound traffic.
Compromised systems first reached out to the attacker’s domains on August 3, only five days after Broadcom’s disclosure. That tight correlation suggests the advisory itself kicked off the campaign, QUIRSO said, with a suspected advanced persistent threat actor behind it.
The company cautions that reverse_ssh alone is not proof of compromise. Pair it with unauthorized installation or odd outbound connections on a vulnerable vCenter appliance, and it becomes an indicator worth urgent investigation.
Chinese espionage actors like UNC5174 have repeatedly turned VMware and vCenter bugs into espionage footholds.
