Critical VMware vCenter RCE (CVE‑2026‑59310) Exploited for Reverse SSH Persistence
What It Is — A directory‑traversal flaw in the VMware vCenter Syslog server (CVE‑2026‑59310) allows an unauthenticated network attacker to execute arbitrary code on the vCenter host.
Exploitability — The vulnerability is being leveraged in an active campaign that installs an open‑source reverse‑SSH tool for persistence and outbound C2. Quirso observed 361 compromised IPs in 47 countries within days of the public advisory. CVSS = 9.8 (Critical).
Affected Products — VMware vCenter Server 9.1 (9.1.0.0300), 9.0 (9.0.2.0100), and 8.0 (8.0 U3k / 8.0 U2f).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control criteria (CC6.1, CC6.2) require that only authorized users can modify management infrastructure; an unauthenticated RCE directly violates this control.
- Continuous evidence of patch management and configuration baselines is essential to demonstrate due diligence during a SOC 2 audit.
- Enterprise buyers increasingly request proof that critical admin platforms are protected against unauthenticated code execution.
Recommended Actions
- Apply the emergency vCenter patches (9.1.0.0300, 9.0.2.0100, 8.0 U3k/U2f) immediately.
- Verify patch compliance across all vCenter instances via automated inventory and configuration tools.
- Enable network segmentation and restrict inbound traffic to the Syslog service to trusted management subnets.
- Deploy detection rules (e.g., Quirso’s YARA for reverse_ssh binaries) and monitor outbound SSH connections.
- Map the vulnerability to SOC 2 Access Control requirements and capture remediation evidence for audit reviewers.
Source: BleepingComputer – Critical VMware vCenter RCE flaw exploited for reverse SSH access