An active cyberattack campaign targeting internet-accessible VMware vCenter instances. Researchers discovered evidence suggesting advanced persistent threat (APT) actors are actively weaponizing CVE-2026-59310, a critical VMware vCenter vulnerability, to gain initial access before deploying reverse SSH tooling to establish persistent backdoors into compromised networks. Deployed Branch Remediated Release Vendor Advisory VMware vCenter 9.1 Version 9.1.0.0300 VMSA-2026-0006.1 VMware vCenter 9.0 Version 9.0.2.0100 VMSA-2026-0006.1 VMware vCenter 8.0 Version 8.0 U3k or 8.0 U2f VMSA-2026-0006.1 The rapid transition from public disclosure to widespread exploitation occurred at an unusually fast pace.
Victim expansion from 2026-08-03 through 2026-08-07 (Image Source: Medium) Exploitation escalated swiftly on August 4, with 151 additional victim IP addresses detected calling home.
Top five victim countries for CVE-2026-59310 include: Germany: 55 unique IPs United States: 41 unique IPs Turkey: 38 unique IPs Iran: 26 unique IPs France: 25 unique IPs Following the successful exploitation of the vCenter Syslog service, the threat actor deployed reverse_ssh, a Go-based open-source SSH-based reverse-shell tool for establishing persistent access. The tool empowers attackers with powerful post-exploitation features: Automated Connect-Backs: Continuously attempts outbound SSH connections to keep remote access channels open. Organizations using VMware vCenter appliances should swiftly implement these protective measures: - Apply Vendor Patches: Upgrade vulnerable vCenter appliances to the latest patched versions (9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f).












