hackers broke into 361 companies' VMware servers in under a week — and they're not leaving

A 9.8-severity bug in vCenter's syslog server went from patch to active exploitation in five days, and attackers are planting permanent backdoors,…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

CVE-2026-59310 is a directory-traversal flaw in vCenter's Syslog server, CVSS 9.8, exploitable by an unauthenticated attacker with network access.

What you need to know

Broadcom disclosed and patched it July 29, 2026 in advisory VMSA-2026-0006; active exploitation began August 3.

What you need to know

Forensics firm QUIRSO tracked 361 victim IPs in 47 countries by August 5 — Germany, the US, Turkey, Iran and France hit hardest.

What you need to know

Attackers deploy the open-source reverse_ssh tool via a malicious cron job for persistent remote access, not just one-time data theft.

What you need to know

Fixed versions: vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f. Broadcom lists no workaround — patching is the only remediation.

Bottom line

If you run vCenter and haven't patched since July 29, do it today — then go hunting for cron jobs before you trust the patch alone.

Aliteq

Read the full story

hackers broke into 361 companies' VMware servers in under a week — and they're not leaving

Read the full story on Aliteq