VMware vCenter : des serveurs français compromis
A critical vulnerability, CVE-2026-59310, affecting VMware vCenter has been actively exploited since August 3rd, with over 360 compromised IP addresses across 47 countries, including a significant number in France. The vulnerability, a directory traversal issue in the vCenter Syslog server, allows remote code execution and was exploited shortly after its disclosure. Attackers are deploying a reverse shell (reverse_ssh) to maintain persistent access and control over compromised systems. Broadcom released a patch on July 29th, 2026, alongside other VMware security updates. The incident highlights a shift from a theoretical risk to an active exploitation campaign, requiring organizations to investigate potential compromise and persistence on exposed vCenter servers.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
