HomeCyber BalkansHackers Take Advantage of Serious VMware vCenter Vulnerability to Implement Reverse SSH...

Hackers Take Advantage of Serious VMware vCenter Vulnerability to Implement Reverse SSH in 47 Countries

Published on

spot_img

Threat researchers have uncovered an active campaign that exploits a critical vulnerability in VMware vCenter, identified as CVE-2026-59310. This alarming discovery has revealed a staggering 361 victim IP addresses across 47 different countries. The exploit concerns a directory-traversal flaw in VMware vCenter’s Syslog server, which poses significant risks for organizations utilizing this software.

This particular vulnerability, assigned a critical severity rating of 9.8 by Broadcom using the CVSS v3 scoring system, allows an attacker who has network access to execute arbitrary code. Given the severity of this issue, Broadcom has emphasized the urgency of patching as the only available remediation, as they have not provided any workarounds. The first public disclosure occurred on July 29, 2026, through Broadcom advisory VMSA-2026-0006, and subsequent updates in advisory VMSA-2026-0006.1 included critical patches for several vCenter versions, specifically versions 9.1.0.0300, 9.0.2.0100, and 8.0 U3k and U2f.

Notably, the exploitation campaign reportedly began just days following the vulnerability’s announcement. According to insights from QUIRSO GmbH’s Threat Research team, attacker-controlled infrastructure began receiving connections from compromised systems on August 3, just five days post-disclosure. Their data indicate a rapid escalation in activity, with an additional 151 victim IPs detected the following day. By August 5, the total number of identified compromised IPs had risen to 343 out of the 361 reported.

The most affected countries include Germany, the United States, Turkey, Iran, and France, accounting for a collective total of 185 observed IP addresses, which is just over half of the overall victim infrastructure identified. However, researchers caution that the number of victim IPs doesn’t directly correlate to the number of organizations impacted. In many cases, a single organization may operate multiple public-facing systems, and overlapping hosting or cloud services could obscure the actual number of compromised entities behind shared IP addresses.

The alarming increase in the number of affected IPs, coupled with the widespread geographical reach of this campaign, implies extensive scanning and opportunistic exploitation of exposed vCenter deployments. Once attackers gain access to these systems, they utilize reverse SSH tooling, a legitimate open-source SSH-based framework, to maintain persistent remote access. This tool allows for outbound connections to the attacker’s infrastructure, enabling functionalities such as port forwarding, file transfers, and management of remote shells.

The use of reverse SSH is particularly concerning because it establishes a resilient communication path for intruders. Since the compromised vCenter appliance initiates the outbound connection, intruders can regain access even if initial exploitation activities have been curtailed. While the presence of reverse SSH alone does not definitively indicate a compromise, experts urge security teams to prioritize investigations into unauthorized binaries, anomalous outbound SSH sessions, or suspicious process executions on unpatched vCenter servers.

Organizations are strongly advised to conduct a thorough audit of all internet-accessible vCenter systems, confirming the installed software versions and promptly applying the critical patches provided by Broadcom. The vendor’s response guidelines also extend to include VMware Cloud Foundation, vSphere Foundation, and Telco Cloud products, emphasizing the urgency for a comprehensive threat mitigation strategy.

To further enhance their security posture, security teams are encouraged to engage in several proactive measures. These include reviewing vCenter logs and outbound network telemetry from August 3 onward, searching for any unauthorized reverse SSH binaries and investigating persistence mechanisms, as well as looking for unusual connections from vCenter appliances to unfamiliar external hosts. It is also wise to restrict management-plane exposure and isolate potentially compromised appliances while conducting forensic investigations.

Given the brief window between the discovery of the vulnerability and its active exploitation, internet-facing vCenter instances that remain unpatched should be treated with caution—potentially compromised until proven otherwise. As cyber threats continue to evolve and proliferate, vigilance and swift action remain key in safeguarding organizational infrastructures from harmful incursions.

Source link

Latest articles

Closing Security Gaps at the Intersection of Digital and Physical Access

Enhancing Access Management in Risk Strategies Amid Evolving Threats Access management stands at the forefront...

Russian-Linked Hackers Breach Polish Power Plant OT via APN

Polish CERT Reports Insights from Cyber-Attack on Energy Infrastructure Amid Russian Campaign The Polish Computer...

Gunra Ransomware Exploits Vulnerabilities in Fortinet FortiOS and FortiProxy to Compromise Networks

Rising Threat: Gunra Ransomware Targets Critical Infrastructure Cybersecurity and intelligence agencies from South Korea and...

Gunra Ransomware Targets Critical Infrastructure by Exploiting Fortinet Vulnerabilities

Gunra Ransomware Targets Government and Critical Infrastructure: Joint Advisory Issued by US and South...

More like this

Closing Security Gaps at the Intersection of Digital and Physical Access

Enhancing Access Management in Risk Strategies Amid Evolving Threats Access management stands at the forefront...

Russian-Linked Hackers Breach Polish Power Plant OT via APN

Polish CERT Reports Insights from Cyber-Attack on Energy Infrastructure Amid Russian Campaign The Polish Computer...

Gunra Ransomware Exploits Vulnerabilities in Fortinet FortiOS and FortiProxy to Compromise Networks

Rising Threat: Gunra Ransomware Targets Critical Infrastructure Cybersecurity and intelligence agencies from South Korea and...