HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical VMware vCenter RCE (CVE-2026-59310) Actively Exploited for Reverse SSH Persistence

A critical directory‑traversal flaw (CVE‑2026‑59310) in VMware vCenter Syslog server is being leveraged by an unauthenticated attacker to install a reverse‑SSH persistence tool. 361 IPs across 47 countries have been observed, prompting immediate patching and tighter access controls for SOC 2 compliance.

LiveThreat™ Intelligence · 📅 August 14, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Critical VMware vCenter RCE (CVE‑2026‑59310) Exploited for Reverse SSH Persistence

What It Is — A directory‑traversal flaw in the VMware vCenter Syslog server (CVE‑2026‑59310) allows an unauthenticated network attacker to execute arbitrary code on the vCenter host.

Exploitability — The vulnerability is being leveraged in an active campaign that installs an open‑source reverse‑SSH tool for persistence and outbound C2.  Quirso observed 361 compromised IPs in 47 countries within days of the public advisory.  CVSS = 9.8 (Critical).

Affected Products — VMware vCenter Server 9.1 (9.1.0.0300), 9.0 (9.0.2.0100), and 8.0 (8.0 U3k / 8.0 U2f).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control criteria (CC6.1, CC6.2) require that only authorized users can modify management infrastructure; an unauthenticated RCE directly violates this control.
  • Continuous evidence of patch management and configuration baselines is essential to demonstrate due diligence during a SOC 2 audit.
  • Enterprise buyers increasingly request proof that critical admin platforms are protected against unauthenticated code execution.

Recommended Actions

  • Apply the emergency vCenter patches (9.1.0.0300, 9.0.2.0100, 8.0 U3k/U2f) immediately.
  • Verify patch compliance across all vCenter instances via automated inventory and configuration tools.
  • Enable network segmentation and restrict inbound traffic to the Syslog service to trusted management subnets.
  • Deploy detection rules (e.g., Quirso’s YARA for reverse_ssh binaries) and monitor outbound SSH connections.
  • Map the vulnerability to SOC 2 Access Control requirements and capture remediation evidence for audit reviewers.

Source: BleepingComputer – Critical VMware vCenter RCE flaw exploited for reverse SSH access

📰 Original Source
https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →