Published Security3 min read
vCenter's July Syslog Patch Arrived Five Days Before the Implants Did
Quirso counted 361 victim IP addresses in 47 countries by August 7, with reverse_ssh dropped for outbound persistence.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Broadcom disclosed CVE-2026-59310 on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server.
- The bug was disclosed on July 29, when Broadcom patched it alongside four other security defects in multiple VMware products.
- Broadcom's advisory states: "A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code." The flaw can be exploited by an unauthenticated attacker with network access.
- CVE-2026-59310 carries a CVSS score of 9.8.
- Broadcom provides no workarounds or mitigations and urges administrators to apply the emergency update and consult the FAQ post.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Broadcom disclosed and patched CVE-2026-59310, a critical directory traversal bug in the VMware vCenter Syslog server, on July 29 [1][2]. Five days later, according to incident response firm Quirso, compromised systems began calling out to attacker infrastructure, and by August 7 the firm had counted 361 victim IP addresses across 47 countries [7][10].
The flaw itself is the kind that does not require much operator imagination: Broadcom's advisory says an actor with network access to vCenter can execute arbitrary code, no authentication needed, with a CVSS score of 9.8 [3][4]. There are no workarounds and no mitigations, only the emergency update [5]. The fixed builds are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f depending on the branch [6].
The timeline is the part worth internalising. Quirso says first connections appeared on August 3, 151 new victim IPs were observed on August 4, the cumulative count hit 343 by August 5, and 361 by August 7 [7][8][9][10]. That means roughly 95 percent of observed victim IPs showed up in the first three days, with only 18 added over the following two [11][12]. This was not a slow burn. It was a sweep of the internet-exposed population, executed while most change windows were still being scheduled. Quirso allows that the attacker may have had prior knowledge of the bug, but says the correlation with disclosure suggests the advisory was the starting gun [13].
Post-exploitation, Quirso reports the attacker deployed reverse_ssh, an open-source SSH reverse shell framework, to hold an outbound control channel from compromised hosts and bypass controls that block inbound connections [14][15]. The operational consequence follows from the mechanics rather than from any vendor statement: an outbound channel established before the update survives the update. Applying 8.0 U3k today removes the entry route and leaves the tenant. Any vCenter that was web-accessible and running a pre-July-29 build between August 3 and now should be handled as a compromise investigation, not a patch ticket.
Quirso has published a generic YARA rule for reverse_ssh client binaries, with the caveat that legitimate penetration testing use of the same tool will fire it, so detections need corroboration through unauthorised installations and unexpected outbound connections [16][17]. Two limits on the numbers: Quirso states that victim IP counts do not map to victim organisations, because some addresses belong to hosting providers, cloud networks, or shared infrastructure [18]. And the firm attributes the campaign to an APT actor while providing no supporting evidence, withholding indicators because of ongoing coordination with law enforcement [19]. More than half the affected IPs sit in Germany, the United States, Turkey, Iran, and France [20]. Broadcom had not responded to BleepingComputer's request for comment on Quirso's findings by publication [21].
Watch for the promised follow-up from Quirso covering the attacker's infrastructure, techniques, persistence, and post-exploitation activity, which is where usable indicators would come from [22]. Until those land, hunting has to be behavioural: outbound SSH from vCenter appliances to addresses nobody can account for.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Broadcom disclosed CVE-2026-59310 on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server.
- [2]
The bug was disclosed on July 29, when Broadcom patched it alongside four other security defects in multiple VMware products.
- [3]
Broadcom's advisory states: "A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code." The flaw can be exploited by an unauthenticated attacker with network access.
- [5]
Broadcom provides no workarounds or mitigations and urges administrators to apply the emergency update and consult the FAQ post.
- [6]
The vCenter releases that address the issue are 9.1.0.0300 for vCenter 9.1, 9.0.2.0100 for vCenter 9.0, and 8.0 U3k or 8.0 U2f for vCenter 8.0 depending on the branch.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comIonut ArghireAug 13Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
- bleepingcomputer.comBill ToulasAug 13Critical VMware vCenter RCE flaw exploited for reverse SSH access
Additional citations
- BleepingComputer
- SecurityWeek
- Broadcom advisory, quoted by SecurityWeek and BleepingComputer



