361 Internet-connected VMware vCenter systems across 47 countries were identified as compromised in an active campaign exploiting CVE-2026-59310, according to digital forensics firm QUIRSO.
CVE-2026-59310: a critical directory traversal in vCenter Syslog Server
Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog Server. The vendor said the flaw "could be exploited by an unauthenticated attacker with network access to execute arbitrary code." Broadcom released emergency updates for affected vCenter branches and provided no workarounds or mitigations, urging system administrators to apply the update and consult the vendor FAQ for further information.
The affected builds cited by the vendor are specific: vCenter 9.1 update 9.1.0.0300, vCenter 9.0 update 9.0.2.0100, and vCenter 8.0 updates 8.0 U3k or 8.0 U2f depending on the branch. VMware vCenter is described by the vendor as centralized management software that controls, monitors, and configures virtual machines, ESXi servers, configurations, and access permissions — capabilities that make the product a frequent target because successful exploitation can give attackers broad control over multiple critical systems.
Campaign timeline and geographic scope observed by QUIRSO
QUIRSO reported that systems began connecting to attacker-controlled infrastructure on August 3 — five days after Broadcom's July 29 disclosure and emergency patch. The campaign expanded rapidly: 151 new victim IP addresses were observed on August 4, the count reached 343 on August 5, and QUIRSO identified a total of 361 victim IPs by August 7. The compromises span 47 countries, with more than half of the observed victim IPs located in Germany, the United States, Turkey, Iran, and France.
BleepingComputer reached out to Broadcom for a statement about QUIRSO’s findings but had not received a response by the time of publication.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageReverse SSH deployment for persistence and outbound command-and-control
After gaining initial access to vulnerable vCenter systems, the attacker deployed the open-source reverse_ssh framework to establish persistence and remote access. QUIRSO described the reverse SSH connection as providing an outbound command-and-control (C2) channel; such outbound channels can also help bypass firewalls and other network security measures by initiating connections from inside a target’s environment to attacker infrastructure.
QUIRSO released a generic YARA rule intended to detect reverse_ssh client binaries, while noting that legitimate uses of the tool will also trigger the detection. The researchers said they believe an advanced persistent threat (APT) actor is behind the exploitation activity, but they provided no evidence to support that assessment in the initial disclosure and are withholding specific indicators while coordinating with law enforcement authorities.
Detection, vendor guidance, and the limits of prevention
Broadcom’s public guidance is unambiguous: apply the emergency update and consult the accompanying FAQ; Broadcom does not offer workarounds or mitigations. QUIRSO’s public detection contribution is a generic YARA rule for reverse_ssh binaries, which defenders can deploy but should interpret carefully because it will flag legitimate instances as well as malicious ones.
A contextual note cited in the reporting references the Blue Report 2026: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments — a reminder that an initial exploit followed by credential use and persistence can defeat prevention-focused controls.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Patch immediately to the specific builds Broadcom listed for vCenter 9.1, 9.0, and 8.0; deploy the QUIRSO YARA rule with awareness that it can flag legitimate reverse_ssh usage; and monitor for outbound connections consistent with reverse SSH C2 behavior.
- Policymakers and regulators: The campaign demonstrates rapid exploitation of a publicly disclosed critical flaw within days of the vendor advisory, highlighting coordination needs between vendors, incident responders, and law enforcement as QUIRSO noted they are doing.
- Affected enterprises and procurement leaders: Systems that centralize control of virtual infrastructure are high-value targets; apply the emergency updates Broadcom published and validate whether vCenter instances are exposing the Syslog Server component to networks that could reach unauthenticated attackers.
The record compiled so far is concrete and fast-moving: a critical directory traversal disclosed on July 29, mass scanning and exploitation within days, deployment of an open-source reverse SSH tool for persistence, and 361 compromised IPs identified by August 7. QUIRSO has signaled a fuller report is forthcoming; until then, administrators who run VMware vCenter should treat Broadcom’s updates as urgent and assume that initial-access compromises can quickly evolve into persistent, outbound-controlled access.




