VMware vCenter Syslog Server CVE-2026-59310 used for reverse SSH
Source headline: Critical VMware vCenter RCE flaw exploited for reverse SSH access
Intelligence Summary
A patched critical flaw in VMware vCenter Syslog Server, CVE-2026-59310, is reportedly being exploited in the wild. The active campaign uses the vulnerability to deploy a reverse SSH tool. This approach is intended to enable persistence and remote access. The article does not provide a CVSS score or victim count. Users running the affected VMware vCenter Syslog Server should apply the available patch and review systems for indicators of the reverse SSH tool.
Recommended Action
Check whether your VMware vCenter Syslog Server deployment is affected by CVE-2026-59310 and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.