{"id":1146,"date":"2026-08-13T09:55:29","date_gmt":"2026-08-13T07:55:29","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1146"},"modified":"2026-08-17T09:56:03","modified_gmt":"2026-08-17T07:56:03","slug":"critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/08\/13\/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access\/","title":{"rendered":"Critical VMware vCenter RCE flaw exploited for reverse SSH access"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran, and France.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Broadcom disclosed CVE-2026-59310 on July 29 and described it as a&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes\/\" rel=\"noreferrer noopener\" target=\"_blank\">critical directory traversal vulnerability<\/a>&nbsp;in the vCenter Syslog server that &nbsp;could be exploited by an unauthenticated attacker with network access to execute arbitrary code.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/08\/13\/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access\/\" target=\"_self\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access\/\">Critical VMware vCenter RCE flaw exploited for reverse SSH access<\/a><span class=\"screen-reader-text\">: Critical VMware vCenter RCE flaw exploited for reverse SSH access<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran,&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[72],"class_list":["post-1146","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-72"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1146"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1146\/revisions"}],"predecessor-version":[{"id":1147,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1146\/revisions\/1147"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}