1. Basic Information
- Original Title: Critical VMware vCenter RCE flaw exploited for reverse SSH access
- Source: BleepingComputer, Broadcom, CISA
- Published Date: 2026-08-13
- Updated Date: 2026-09-15
- Severity: Critical
- Severity Basis: This is a CVSS 9.8 unauthenticated remote code execution vulnerability. In August, reports identified 361 affected IP addresses across 47 countries along with the setup of reverse SSH access. While CISA KEV lists this vulnerability as known to be exploited in ransomware activity, available reports do not confirm specific impacts such as virtual machine encryption.
- Original Link: Critical VMware vCenter RCE flaw exploited for reverse SSH access
- Related Source: BleepingComputer: CISA: Critical VMware RCE flaw now exploited by ransomware gangs
- Related Source: Broadcom Security Advisory VMSA
- Related Source: CISA Known Exploited Vulnerabilities Catalog
- Related Source: CISA: KEV Official Data
- Reason for Update: CISA KEV marked
knownRansomwareCampaignUseas Known, confirming exploitation in ransomware activity. Consequently, impact assessments and investigation scopes were updated. Specific threat actors, encryption targets, and post-compromise actions remain undisclosed, and a direct link to the August reverse SSH activity has not been confirmed. - Related Entities: reverse_ssh, Ransomware, CVE-2026-59310, VMware vCenter Server, vCenter Syslog Server, VMware ESXi
2. Executive Summary
CISA has confirmed that CVE-2026-59310, a path traversal vulnerability in the vCenter Syslog Server leading to unauthenticated remote code execution, is being actively exploited in ransomware campaigns. Organizations must update to patched versions, isolate management networks, and inspect systems for past execution and persistence artifacts.
3. Attack Flow
Flow 1: Unauthenticated Remote Code Execution and Reverse SSH Reported in August
- An attacker connects over the network to an unpatched vCenter Syslog Server.
- The attacker exploits CVE-2026-59310 to achieve arbitrary code execution on vCenter without authentication.
- The attacker creates a cron job to launch
reverse_sshfor persistence. - The vCenter appliance initiates an outbound SSH connection to an external C2 server, maintaining a remote shell. Because the connection originates outbound, inbound-only firewall rules may fail to block it.
Flow 2: Ransomware Activity: Confirmed Scope
- The CISA KEV catalog indicates that this vulnerability has been exploited in ransomware campaigns.
- Post-exploitation tools, threat actor identities, interactions with ESXi and virtual machines, and encryption procedures have not been publicly disclosed. This activity is not treated as definitively linked to the August reverse SSH incidents.
4. Attacker Position and Execution Location
- The attacker must have network reachability to the vCenter Syslog Server. Authentication is not required to exploit this vulnerability.
- According to the August reports, code execution, cron jobs, and
reverse_sshoperate directly on the vCenter appliance. - The execution location after compromise in ransomware campaigns and the scope of impact on ESXi and virtual machines have not been publicly disclosed.
5. Visibility for Victims and Administrators
Victims
- Exploitation of this vulnerability does not require any action from regular users.
- Inference: If subsequent attacks disrupt business operations, users may notice symptoms such as virtual machine outages, though such symptoms are not confirmed for this specific issue.
Administrators
- Inference: Depending on logging configurations, administrators may find suspicious requests to the Syslog Server, unknown files and processes, cron jobs, and outbound SSH traffic.
- Inference: If managed systems are manipulated, vSphere tasks and audit logs may retain records of changes to permissions, virtual machines, or snapshots.
6. Success and Failure Conditions
Success Conditions
- The attacker must be able to reach an unpatched vCenter Syslog Server over the network. Affected versions and patch levels must be verified per product line.
- For the persistence reported in August, post-exploitation file creation, cron modifications, and process execution must succeed.
- Maintaining remote control via reverse SSH requires communication with an external C2 server. Blocking this outbound traffic alone does not disprove initial code execution or guarantee that other secondary actions were prevented.
Failure Conditions
- Update to the patched version corresponding to the product line. Official remediation versions include 9.1.0.0300 for the 9.1 branch, 9.0.2.0100 for the 9.0 branch, and U3k or U2f for the 8.0 branch. For version 7.0, verify status with Broadcom if an extended support contract is active. For configurations such as VCF, follow official patch matrices and deployment procedures.
- Broadcom has not provided any workarounds for this vulnerability.
- Inference: Restricting inbound access to management networks narrows the attack surface, but it does not replace applying software patches.
- Inference: Outbound traffic filtering targets C2 communication, file and cron monitoring targets persistence, and permission audits target subsequent actions. The mere presence of monitoring capabilities does not prove that an attack was blocked.
7. Impact of Successful Exploitation
- Successful exploitation allows arbitrary code execution on vCenter. August reports noted the maintenance of access via reverse SSH.
- CISA has confirmed exploitation in ransomware campaigns. This alone does not confirm whether managed virtual machines were encrypted or backups were deleted.
- Inference: Because vCenter is a centralized management point, compromise of its privileges or stored data could spread to managed environments; therefore, specific operational actions require further investigation.
8. Observable Logs
- Inference: Email inspection and user interaction are not required to exploit this unauthenticated vulnerability.
Proxy / SWG / DNS
- Inference: Check for DNS lookups to unknown destinations and outbound traffic originating from vCenter. SSH traffic may not necessarily be recorded by HTTP proxies.
Endpoint / EDR
- Inference: Check operating system audit logs, file modification records, and available EDR solutions for
reverse_ssh, unknown ELF binaries, cron jobs, and shell execution.
Identity / IdP
- Inference: Review available logs for unauthorized authentication or operations involving vCenter Single Sign-On (SSO), permissions, tokens, and certificates.
SaaS / Cloud
- Inference: Review vSphere tasks as well as ESXi, virtual machine, and backup logs for power operations, snapshots, and datastore modifications.
Network
- Inference: Correlate requests to the Syslog Server, long-duration outbound connections, and suspicious connections within the management network. Encrypted traffic contents cannot be determined from flow data alone.
9. Determining Attack Success
Confirmed via Public Information
-
Malware Execution or Successful Authentication Confirmed: Public Information: August reports confirmed persistence and C2 via cron and
reverse_ssh. This does not constitute proof of specific details regarding September ransomware activities.
Internal Assessment Criteria
- Attack Attempt Observed (Success Unconfirmed): Criteria: Only scanning activity or attack requests are observed, with no evidence of execution. In the absence of sufficient logs, the lack of execution records does not prove that the attack failed.
- Initial Execution Confirmed: Criteria: Attack requests are correlated with the execution of resulting processes or commands. The mere presence of unknown files or error messages does not confirm arbitrary code execution.
- Information Theft or Session Compromise Confirmed: Criteria: Evidence of unauthorized use of credentials, certificates, or sessions, or data exfiltration to an attacker, is confirmed. Normal usage or the mere presence of credentials does not constitute a compromise.
- Subsequent Compromise Confirmed: Criteria: Unauthorized operations against ESXi, virtual machines, or backups, such as encryption or destruction, are supported by concrete logs. CISA KEV classifications indicate exploitation in ransomware campaigns, but do not individually confirm specific impacts at this stage.
10. Investigation Playbook
Triggers
- Inference: Investigations are triggered by vulnerable vCenter installations, suspicious requests, cron jobs,
reverse_sshactivity, or KEV exploitation intelligence.
Initial Response
- Inference: Verify the product branch and build, patch application timestamps, historical exposure duration, initial suspicious requests, and current processes and connections.
Endpoints and Servers
- Inference: Preserve cron configurations, process lineage, file systems, operating system audit and syslog data, and binary hashes.
Identity and Cloud
- Inference: Review vCenter SSO, permission changes, unauthorized use of tokens and certificates, and vSphere tasks.
Subsequent Operations
- Inference: Trace operations on ESXi hosts and virtual machines, snapshots, datastores, backup deletions, encryption, and data exfiltration in chronological order.
Containment
- Inference: Isolate management interfaces and C2 communications, preserve logs, and decide whether to apply patches or rebuild compromised appliances. Evaluate whether credentials or certificates suspected of being exposed require rotation, and assess and address impacts on authentication and integrated services.
Classification Categories
- Inference: Differentiate between scanning, attack attempts, code execution, persistence and C2, unauthorized use of administrative privileges, and actual impact on ESXi and virtual machines.
11. Defense and Detection Concepts
Single Events
- Inference: Investigate unknown cron jobs on vCenter,
reverse_ssh, and requests suspected of path traversal against the Syslog Server. Indicator matches alone do not prove successful CVE exploitation.
Chronological Correlation
- Inference: Correlate unauthenticated requests, corresponding execution events, cron modifications, reverse SSH activity, and operations targeting managed systems or backups.
Threat Hunting
- Inference: Verify all vCenter versions and historical exposure ranges, tracing backward from August 3 to review cron jobs, ELF binaries, SSH activity, and virtual machine or backup operations within the log retention period.
Log Deficiencies
- Inference: Verify the collection scope and retention period for appliance execution records, requests, outbound traffic, vSphere tasks, and backup audit logs. Missing logs limit the ability to determine the full scope of impact.
Priority Mitigations
- Inference: Update to version 9.1.0.0300 for the 9.1 branch, 9.0.2.0100 for the 9.0 branch, U3k or U2f for the 8.0 branch, or later patched versions containing the same fixes, and verify the post-update build. Concurrently, isolate management interfaces and conduct compromise investigations.
12. Facts, Inferences, and Hypotheses
Facts
- CVE-2026-59310 is a path traversal vulnerability in the vCenter Syslog Server that leads to unauthenticated remote code execution over the network. Broadcom assigns a CVSS v3 score of 9.8.
- Broadcom released patches on July 29, 2026, stating that no workarounds are available. Official patch matrices list versions 9.1.0.0300, 9.0.2.0100, 8.0 U3k, and 8.0 U2f.
- August reports identified 361 affected IP addresses across 47 countries and persistence established by launching open-source
reverse_sshvia cron. Note that IP counts do not represent organization counts. - In official CISA KEV data,
knownRansomwareCampaignUseis set toKnownandforensicTriageis set toYes. While this indicates exploitation in ransomware activity, it does not detail specific operations such as virtual machine encryption. - According to September 15 reports, Shadowserver tracked over 450 vCenter instances exposed to the internet. Internet exposure counts do not equate to compromised instances.
- Current CISA intelligence and public reports do not disclose the ransomware threat actor groups, tools used, encryption targets, or specific post-compromise procedures.
Inferences
- Compromise of vCenter can potentially impact ESXi hosts, virtual machines, backups, snapshots, and credentials, though the specific scope of impact in recent ransomware incidents remains publicly undisclosed.
- In addition to known
reverse_sshindicators, investigations must also examine the use of administrative privileges and modifications to virtual machines and backups. It remains undetermined whether newly identified exploitation is attributed to a different threat actor than the August activity.
Hypotheses
No additional hypotheses. Unverified items are documented in Unknowns and Further Investigation.
13. MITRE ATT&CK Mapping
- T1190 Exploit Public-Facing Application (Confidence: high): Attackers exploit unauthenticated vulnerabilities in the vCenter Syslog Server over the network.
- T1053.003 Scheduled Task/Job: Cron (Confidence: high): August reports indicate persistence established via cron to execute reverse_ssh.
- T1572 Protocol Tunneling (Confidence: high): August reports indicate outbound reverse SSH used to maintain remote access.
14. Unknowns and Further Investigation
- Ransomware threat actor groups, tools used, timing of compromise, and number of victim organizations.
- Specific operations performed against ESXi and virtual machines from vCenter.
- Presence and sequence of encryption, data theft, and backup deletion.
- Relationship between ransomware exploitation and the August reverse SSH activity.
15. Impact on SOCs and Organizations
Because vCenter serves as the centralized management point for virtualized infrastructure, unpatched environments vulnerable to ransomware exploitation require prioritized remediation. Verify patched versions corresponding to each product line, and review historical logs for execution, cron jobs, and outbound SSH activity prior to patching. Confirm impacts to managed systems and backup anomalies using actual log data rather than extrapolating from KEV classifications, and evaluate whether credentials and certificates require rotation.
16. Summary by Role
- SOC: Chronologically trace attack requests, execution, cron activity, reverse SSH, and operations against vSphere, virtual machines, and backups, while distinguishing between KEV classifications and individual victim impacts.
- Administrators: Update to patched versions matching the product line, verify builds, restrict management interfaces and outbound traffic, and plan compromise investigations alongside necessary credential and certificate rotations.
- Users: User interaction is not required for exploitation. Report virtual machine outages or business system anomalies to administrators.
Top comments (0)