Active exploitation targeting enterprise virtualization management infrastructure has been uncovered, with advanced threat actors exploiting a critical directory traversal bug to achieve remote code execution. Attackers are deploying persistent reverse shell frameworks to maintain covert control over compromised vCenter servers across global targets.
The vulnerability, tracked as CVE-2026-59310 with a CVSS score of 9.8, impacts VMware vCenter Server installations managed by Broadcom. The issue stems from improper path validation within the Syslog logging service daemon. An unauthenticated network actor with access to vCenter web ports can craft malicious directory traversal requests to write arbitrary files into execution paths, granting full system code execution. Incident telemetry reveals threat actors deploy an open source SSH framework named reverse_ssh to initiate persistent outbound management connections that bypass inbound firewall blocks.
Subverting central virtual infrastructure controllers destroys logical separation across cloud hosting environments. Because vCenter appliances manage virtual machine snapshots, storage datastores, and hypervisor host clusters, an administrative takeover allows threat actors to capture virtual disk files, deploy secondary implants across virtual machines, and disrupt core enterprise operations.
– Apply official software patches released by Broadcom across all VMware vCenter Server deployments immediately.
– Isolate vCenter management interfaces on restricted administrative subnets, completely removing public internet exposure.
– Inspect network telemetry for unauthorized outbound SSH connections or unexpected reverse shell processes executing under syslog daemon contexts.
– Audit local vCenter account rosters and session histories for unrecognized administrative logins or API token creations.
Virtualization management plane protection demands strict interface isolation and prompt security updates to ensure central cloud controllers remain completely shielded from unauthenticated remote code execution. #CodeDefence #VMware #vCenter #Broadcom #RCE #DirectoryTraversal #CloudSecurity #AppSec
/
