Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical remote code execution flaw (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited to install a reverse SSH tool for persistent remote access.

A critical VMware vCenter Syslog Server flaw, CVE-2026-59310, is being actively exploited to deploy a reverse SSH tool for persistent remote access. The vulnerability, which allows remote code execution, was recently patched. Attackers are using the exploit in an active campaign to gain and maintain access to affected systems.