A critical vulnerability in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access, according to BleepingComputer, citing findings from digital forensics and incident response firm QUIRSO. The flaw is tracked as CVE-2026-59310. BleepingComputer reports that Broadcom disclosed it on July 29 as a critical directory traversal vulnerability in the vCenter Syslog server. According to that disclosure as summarized by BleepingComputer, an unauthenticated attacker with network access could exploit the bug to execute arbitrary code. QUIRSO’s findings, as reported by BleepingComputer, put the observed footprint at 361 victim IP addresses across 47 countries. More than half of the identified IP addresses were in Germany, the United States, Turkey, Iran, and France. The figures are IP-based, not a count of affected organizations. The campaign appears to have moved quickly after public disclosure. BleepingComputer reports that QUIRSO saw compromised systems begin connecting to attacker-controlled infrastructure on August 3, five days after Broadcom disclosed the issue and released an emergency patch. QUIRSO then observed 151 new victim IP addresses on August 4, a rise to 343 by the next day, and a total of 361 by August 7. After gaining access to vulnerable vCenter systems, the attacker deployed the open-source reverse_ssh framework, according to the report. The tool can create an outbound command-and-control channel, giving the operator remote access and a persistence mechanism. BleepingComputer notes that an outbound reverse SSH connection can also help bypass some firewall or network controls. The target matters because VMware vCenter is centralized management software for VMware virtual infrastructure, including virtual machines, ESXi servers, configurations, and access permissions. BleepingComputer notes that vCenter is frequently targeted because control of the management plane can give attackers leverage over multiple critical systems, with potential paths to data theft or operational disruption. Broadcom provides no workaround or mitigation for the issue and is urging administrators to apply the emergency update, according to BleepingComputer. QUIRSO has released a generic YARA rule for detecting reverse_ssh client binaries, but the report cautions that legitimate uses of the tool can also trigger the alert. QUIRSO believes an advanced persistent threat actor is behind the exploitation activity, BleepingComputer reports, though the researchers did not provide evidence for that attribution and are withholding specific indicators while coordinating with law enforcement. QUIRSO is planning a more detailed follow-up report on the attacker infrastructure, techniques, persistence, and post-exploitation activity. BleepingComputer said it contacted Broadcom about QUIRSO’s findings but had not received a response by publication time. Who benefits: Attackers benefit from any delay in patching internet- or network-reachable vCenter systems. Defenders benefit from Broadcom’s patch and QUIRSO’s published generic detection rule, though the latter requires validation because legitimate reverse_ssh usage may alert. Who's exposed: Organizations running vulnerable VMware vCenter Syslog Server instances are exposed, especially where attackers have network access to the service. The provided reporting does not establish how many organizations, as opposed to IP addresses, were affected.