Overview
- Broadcom published fixes for CVE-2026-59310 on July 29, 2026, and security teams have confirmed active exploitation of that directory-traversal flaw in the vCenter Syslog service that allows unauthenticated remote code execution.
- Investigators first observed compromised vCenter systems contacting attacker infrastructure on August 3, 2026, and forensics show the exploit created a malicious cron job and launched the open-source reverse_ssh client to hold persistent outbound access.
- Quirso and other responders reported roughly 361 unique victim IP addresses across 47 countries, but investigators warn those IPs can represent hosting or shared infrastructure and do not map directly to the number of affected organizations.
- Defenders are urged to apply Broadcom’s patched vCenter releases (9.1.0.0300, 9.0.2.0100, 8.0 U3k/8.0 U2f), isolate the management plane, block or allowlist egress to prevent reverse SSH callbacks, and perform forensic checks for unknown binaries, cron jobs, and outbound connections.
- Attribution remains unresolved, the campaign echoes past espionage targeting VMware management appliances, and organizations should treat patching as only the first step because ongoing backdoors can let attackers reach ESXi hosts and virtual machines if not removed.