Broadcom VMware vCenter administrators are grappling with an intrusion campaign targeting CVE-2026-59310, a severe directory-traversal vulnerability in the vCenter Syslog Server This article explores vulnerability vcenter. . Threat researchers at QUIRSO identified 361 unique victim IP addresses across 47 countries, indicating a sophisticated attack using this flaw for code execution and remote access.
VMware vCenter Directory Traversal Vulnerability Attack Activity surged: 151 additional victim IP addresses were detected on August 4, and 343 of the 361 observed IPs, approximately 95%, had been identified by August 5. The data reflects infrastructure rather than a count of verified organizations; one entity might use multiple IPs, while cloud, hosting, and shared networks can represent numerous unrelated tenants.
Administrators should inventory vCenter deployments, prioritize instances reachable from untrusted or broad internal networks, and apply the appropriate fixed release: vCenter 9.1.0.0300, 9.0.2.0100, or the relevant vCenter 8.0 U3k/U2f branch update. Defenders must limit vCenter access to authorized administrative networks, scrutinize outbound connections on vCenter appliances, and detect unusual reverse SSH binaries and SSH tunneling activities. The QUITSORO team has released a generic YARA rule for detecting reverse SSH builds, but it's crucial to correlate these findings with process execution logs, network telemetry, and change records.












