ON
← Back to feed
Attacks on VMware vCenter by path traversal gap
Germany💻 Technology11 days ago

Attacks on VMware vCenter by path traversal gap

IT-Sicherheitsforscher von Quirso haben gemeldet, dass böswillige Akteure eine Sicherheitslücke in VMware vCenter Syslog Server ausnutzen, um Schadcode einzuschleusen und auszuführen. Die Schwachstelle (CVE-2026-59310) wurde von Broadcom im Juli 2026 offengelegt und mit einem CVSS-Rating von 9.8 bewertet. Obwohl ein Software-Patch bereitsteht, ist keine temporäre Gegenmaßnahme verfügbar. Forscher haben 361 kompromittierte VMware vCenter-Instanzen identifiziert, wobei 55 davon in Deutschland registriert wurden. Die Angriffe begannen kurz nach der Offenlegung der Schwachstelle und führten zu einer schnellen Ausbreitung. Die Angreifer nutzen das open-source Tool 'reverse_ssh' für den Zugang, was auf gezielte Cyberattacken hinweist. IT-Administratoren werden gebeten, ihre Systeme auf den neuesten Stand zu bringen und auf ungewöhnliche Software wie 'reverse_ssh' zu prüfen.

Attackers have exploited a critical vulnerability in VMware vCenter’s Syslog Server, enabling them to inject and execute malicious code. The breach was identified by cybersecurity researchers at Quirso, who detailed their findings on the Medium platform. The flaw, known as CVE-2026-59310 with a CVSS score of 9.8 and classified as critical, allows attackers to bypass security measures through a path-traversal vulnerability. Broadcom, which acquired VMware, issued a patch in early July this year, urging users to update their systems to versions including vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k, and 8.0 U2f. However, there are no temporary mitigations available, and only applying these updates can effectively close the exploit. The researchers analyzed compromised devices and discovered a large number of affected systems. As of Tuesday this week, they identified 361 IP addresses associated with compromised VMware vCenter instances. Of these, 55 were located in Germany, followed by the United States with 41 addresses and Turkey with 38. The attack campaign began shortly after the vulnerability was disclosed on July 29. The first infected systems contacted the attacker's infrastructure five days later, starting on August 3. Within two days, 343 of the 361 IP addresses had already been detected. The attackers used a technique called "reverse_ssh," an open-source SSH-based reverse-shell framework typically employed during penetration testing. This tool enables automated connections, port forwarding, file transfer, and remote shell management. These capabilities allowed the attackers to maintain persistent access within the compromised networks. IT administrators are advised to verify whether their VMware vCenter Syslog Servers are up to date and to monitor for unexpected software such as reverse_ssh running on their systems. The exploitation of this vulnerability highlights the importance of timely patch management in enterprise environments. Many organizations rely heavily on VMware vCenter for managing virtualized infrastructures, making them prime targets for cybercriminals seeking to gain unauthorized access. The scale of the compromise suggests that the attack may have been orchestrated by well-resourced actors capable of deploying sophisticated techniques to evade detection. Security experts warn that while the immediate threat has been mitigated by updating systems, the potential for long-term damage remains. Compromised systems could serve as entry points for further attacks, potentially leading to data breaches, ransomware deployment, or other forms of cybercrime. The presence of reverse_ssh indicates that the attackers may have established a foothold within the network, allowing them to move laterally and exfiltrate sensitive information. As the situation unfolds, IT professionals are urged to conduct thorough audits of their infrastructure and implement additional monitoring tools to detect anomalous activity. The lack of public disclosure regarding ongoing attacks means that many organizations may still be unaware of their exposure. While Broadcom has released patches, the effectiveness of these solutions depends on prompt action from system administrators. Until all vulnerable systems are patched, the risk of continued exploitation persists.

Go to the primary sources (2)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 7011 days ago
Attacks on VMware vCenter by path traversal gap

IT-Sicherheitsforscher von Quirso haben gemeldet, dass böswillige Akteure eine Sicherheitslücke in VMware vCenter Syslog Server ausnutzen, um Schadcode einzuschleusen und auszuführen. Die Schwachstelle (CVE-2026-59310) wurde von Broadcom im Juli 2026 offengelegt und mit einem CVSS-Rating von 9.8 bewertet. Obwohl ein Software-Patch bereitsteht, ist keine temporäre Gegenmaßnahme verfügbar. Forscher haben 361 kompromittierte VMware vCenter-Instanzen identifiziert, wobei 55 davon in Deutschland registriert wurden. Die Angriffe begannen kurz nach der Offenlegung der Schwachstelle und führten zu einer schnellen Ausbreitung. Die Angreifer nutzen das open-source Tool 'reverse_ssh' für den Zugang, was auf gezielte Cyberattacken hinweist. IT-Administratoren werden gebeten, ihre Systeme auf den neuesten Stand zu bringen und auf ungewöhnliche Software wie 'reverse_ssh' zu prüfen.

Bias read (Center): Der Artikel behandelt eine technische Sicherheitslücke in einem Softwareprodukt und informiert über die Auswirkungen auf IT-Infrastrukturen. Es wird keine politische Haltung oder Meinungsäußerung vertreten, sondern rein sachliche Informationen über Sicherheitsrisiken und Empfehlungen zur Abwehr. Der

Why factuality (85): The article accurately reports on the vCenter directory-traversal vulnerability (CVE-2026-59310) and aligns with the primary source document from Broadcom. It mentions the CVSS score, the affected versions, and the recommended patches. However, it adds information not present in the primary source,

Why objectivity (70): The tone is somewhat alarmist, using phrases like 'bösartige Akteure' and 'Eingenistete Angreifer', which suggest a more dramatic interpretation than the neutral language used in the primary source. The article also emphasizes the scale of the attack without providing direct evidence from the primar

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories