Critical VMware vCenter RCE flaw exploited for reverse SSH access post, augustus 13, 2026augustus 17, 2026 A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran, and France. Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that could be exploited by an unauthenticated attacker with network access to execute arbitrary code. Critical VMware vCenter RCE flaw exploited for reverse SSH access: Critical VMware vCenter RCE flaw exploited for reverse SSH access vulnerability 2026