Nine Days From Patch to 361 Victims
Broadcom published VMSA-2026-0006 on July 29, 2026, disclosing CVE-2026-59310 alongside a companion authentication-bypass flaw, CVE-2026-59309, in VMware vCenter Server versions 8.0, 9.0 and 9.1. Fixed builds were made available the same day: vCenter 9.1.0.0300, vCenter 9.0.2.0100, and vCenter 8.0 U3k or U2f depending on the deployed update track.
QUIRSO GmbH, a German digital-forensics and incident-response firm, says attacker-controlled infrastructure logged its first inbound connections from exploited vCenter systems on August 3, 2026, just five days after the patch shipped. By August 7, the firm had counted 361 distinct victim IP addresses spread across 47 countries, with roughly half concentrated in Germany, the United States, Turkey, Iran and France. QUIRSO published a YARA detection rule alongside its findings but withheld some indicators of compromise while coordinating with law enforcement.
A Syslog Function That Hands Over the Whole Server
CVE-2026-59310 sits in the directory-handling logic of vCenter's Syslog Server component. Broadcom's own advisory states plainly that a malicious actor with network access to vCenter may exploit the issue to execute arbitrary code, and critically, no authentication is required first. That combination, unauthenticated plus system-level code execution, is what earned the flaw its 9.8 out of 10 severity score and what makes any internet-reachable vCenter instance an immediate target rather than a theoretical one.
vCenter is not a peripheral tool. It is the management plane for an organization's entire virtualization estate, the console that provisions, migrates and controls every virtual machine an enterprise runs. A vendor advisory for this specific product should never sit in the same queue as a routine application patch.
Why reverse_ssh Beats the Firewall Rule You Already Have
Rather than opening a listening port on the compromised vCenter server, which most network monitoring is built to flag, the attackers behind this campaign install reverse_ssh, an open-source Go tool that has the compromised machine initiate an outbound SSH connection back to attacker infrastructure. Because the connection is outbound, it can slip past firewall and network policies that are configured to block unsolicited inbound traffic but wave through ordinary-looking outbound sessions, giving the attacker a durable, hands-on-keyboard foothold that survives a simple network segmentation review.
For a device that already sits at the center of an organization's virtualization estate, that persistence mechanism turns a single unpatched vCenter server into a long-lived beachhead rather than a one-time smash-and-grab.
Original Thesis: The KEV Gap Is the Real Story Here
Most vulnerability coverage measures urgency by whether a flaw has landed on CISA's Known Exploited Vulnerabilities catalog, and many patch programs are built, formally or informally, around that same trigger. CVE-2026-59310 breaks that assumption. Independent telemetry from both QUIRSO and security firm Rapid7 documented hundreds of real-world compromises spanning 47 countries within the first week and a half of disclosure, yet as of this writing the CVE has still not appeared in CISA's catalog. A patching workflow that treats KEV inclusion as the signal to escalate a vCenter advisory to emergency status was, by definition, already weeks behind the attackers who found and weaponized this flaw.
The lesson generalizes beyond this one CVE. For infrastructure-tier software like a hypervisor management console, an independent DFIR firm's telemetry or the vendor's own severity score should be enough to trigger emergency patching on its own, without waiting for a government catalog entry that, this time, never arrived on schedule.
What vCenter Operators Should Do Now
Any organization running vCenter 8.0, 9.0 or 9.1 that has not applied the July 29 fixes should treat this as an emergency change, not a scheduled one, and should also confirm the management interface is not directly reachable from the public internet, which it never should be in the first place. Given the outbound persistence method documented here, monitoring outbound SSH connections initiated by infrastructure-tier servers, not just inbound access to them, is now part of a complete detection strategy for this specific campaign.
For EU essential and important entities under NIS2 that operate internet-facing or otherwise exposed vCenter instances during the exploitation window, this incident sits squarely inside the categories the directive was written to capture: unauthenticated remote code execution on infrastructure with confirmed active exploitation and a real prospect of confidentiality, integrity or availability impact across an entire virtualization estate.
Read next: Langflow's Two-Call Chain Handed Root to 295 Attackers | CVSS 9.6 Flaw Hit Load Balancers 792 Times



