Critical vCenter Flaw CVE-2026-59310 Actively Exploited

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/5 · Reconnaissance

Attackers scan the internet for reachable VMware vCenter servers with the unpatched flaw.

T1595 – Active Scanning T1595.002 – Vulnerability Scanning
  • Target: publicly reachable vCenter servers (syslog server)
  • Exploitation started just 5 days after patch release (29 July 2026)
  • Internet-facing systems significantly increase the attack surface
PHASE 2/5 · Initial Access

Attackers gain network access to vCenter without authentication via the critical directory-traversal flaw CVE-2026-59310.

T1190 – Exploit Public-Facing Application
  • CVE-2026-59310 in the vCenter syslog server, CVSS 9.8 (critical)
  • Network-based attack, no authentication or user interaction required
  • QUIRSO observed path-traversal activity in an incident-response case
PHASE 3/5 · Execution

The flaw allows execution of arbitrary code on the management layer.

T1203 – Exploitation for Client Execution
  • Broadcom: "may exploit this issue to execute arbitrary code"
  • Potential full takeover of the vCenter management layer
  • Low attack complexity (per CVSS vector)
PHASE 4/5 · Persistence

Attackers install reverse_ssh to establish a persistent remote-access channel outbound from the compromised machine.

T1505 – Server Software Component T1571 – Non-Standard Port
  • reverse_ssh sets up an outbound reverse shell over SSH
  • Outbound connections to attacker infrastructure from 3 August 2026
  • Shadowserver: all reported victims considered fully compromised
PHASE 5/5 · Impact

The campaign spreads rapidly worldwide, compromising hundreds of systems, including many in Germany.

  • 361 unique victim IP addresses across 47 countries (QUIRSO)
  • 185 IPs attributed to Germany, USA, Turkey, Iran and France
  • 151 new victim IPs on 4 Aug 2026 alone; 95% seen by 5 Aug
Short & clear answers
Frequently asked questions about this incident
As a website operator, am I affected by CVE-2026-59310?
You are only directly affected if you run VMware vCenter yourself or if your hosting, managed-service or cloud provider uses this component for your systems. If you operate an ordinary website without your own vCenter, this specific vulnerability does not affect you directly. However, you carry a supply-chain risk if your provider uses vCenter, so ask them specifically.
How do I check whether my vCenter version is vulnerable?
Log in via the regular administration path; the vSphere Client's "Summary" tab shows the build and version. The patched versions are 9.1.0.0300 (for 9.1.x), 9.0.2.0100 (for 9.0.x), and 8.0 U3k or 8.0 U2f (for the respective 8.0 branch). Any older version in the relevant branch is considered affected, and if in doubt Broadcom advises assuming you are affected.
What exactly do I need to do now?
Create an inventory of all vCenter instances and the providers involved, determine the version, and compare it against the fix matrix. Apply the available patch immediately and check whether the vCenter management interface is reachable from the internet. If a service provider runs it, request written confirmation of the patch status.
How dangerous is this vulnerability?
The flaw is rated critical with a CVSS score of 9.8 out of 10 and is already being actively exploited. An attacker with network access can execute arbitrary code without authentication and without user interaction, potentially leading to full takeover of the VMware management layer. On 10 August 2026 the German BSI added the note "active exploitation reported."
How can I tell whether my server has already been compromised?
A key warning sign is the tool reverse_ssh, which attackers install to maintain persistent access — according to Shadowserver on all reported victims. Watch for unauthorized installations, unexpected outbound connections, and path-traversal activity on a vulnerable vCenter appliance. In combination, these indicators are high-priority and require immediate investigation.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.