Two weeks ago this outlet flagged CVE-2026-59310 as a flaw worth patching immediately precisely because Broadcom had found no evidence of exploitation yet, and that window never lasts. It did not last here either.
From advisory to reverse shell in five days
CVE-2026-59310 is a directory traversal vulnerability in vCenter Server’s Syslog service, rated 9.8 out of 10, that lets an unauthenticated attacker with network access to vCenter execute arbitrary code on the appliance. Broadcom published the fix in VMSA-2026-0006 on 29 July 2026. Researchers tracking the aftermath have now identified 361 unique victim IP addresses across 47 countries showing the same attack pattern: path traversal activity consistent with the flaw, followed within a short window by a malicious cron job that deploys reverse_ssh, an open source tool that opens an outbound SSH tunnel to attacker-controlled infrastructure. Once that tunnel is live, the attacker has persistent remote access that survives a reboot and does not depend on the original vulnerability staying open. The earliest confirmed contact with attacker domains was recorded on 3 August, just five days after the advisory landed.
Germany and France are on the list
Germany, the United States and Turkey are the most heavily represented countries in the exploitation data, with Iran and France also named among the top affected. That is a meaningfully different picture from the low-and-slow, single-target intrusions this class of vulnerability usually produces. A directory traversal RCE in a component as central as vCenter’s Syslog server, combined with an automated, repeatable path to persistence, is close to ideal for opportunistic mass scanning, and the country spread bears that out. Broadcom has since issued an updated advisory, VMSA-2026-0006.1, with revised fixed versions: vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and 8.0 U2f. If your patch tracking still shows the original 29 July version numbers, it is worth confirming you are actually on the current build.
Patching the vulnerability does not remove the backdoor
The detail that matters most for anyone triaging this now: applying the fixed vCenter build closes CVE-2026-59310 but does not evict an attacker who already established a reverse SSH tunnel before the patch went in. Any vCenter instance that was internet-reachable, or reachable from a compromised segment, between 29 July and whenever the patch was actually deployed needs to be checked for the cron persistence mechanism and unexpected outbound SSH connections, not just patched and closed out as resolved.
What this means for European virtualisation estates
vCenter is the control plane for VMware environments that a large share of European banks, hospitals, government agencies and manufacturers run on-premises specifically to keep sensitive workloads under direct, sovereign control. That same centrality is exactly why a network-reachable RCE against it, now confirmed as actively and widely exploited, is not a routine patch cycle item. Under NIS2, a confirmed active-exploitation vulnerability affecting core infrastructure that is patched late, or patched without checking for prior compromise, is difficult to defend as adequate incident response if it surfaces during an audit or a breach investigation.
If your organisation runs VMware vCenter and needs help confirming you are on the corrected build, hunting for reverse SSH persistence on infrastructure that was exposed before the patch, or building a faster detection path for the next advisory like this one, contact Excello Digital. We help European organisations turn a vendor advisory into a verified, clean environment, not just an applied patch.
