CriticalTLP:CLEARGARNET-CSIRT-2026-003

VMware vCenter Server Remote Code Execution Vulnerability (Actively Exploited)

Critical directory-traversal vulnerability in the VMware vCenter Server Syslog service. An unauthenticated attacker with network access to vCenter can execute arbitrary code on the appliance. Broadcom disclosed the flaw in VMSA-2026-0006 on 29 July 2026; incident responders at QUIRSO GmbH observed in-the-wild exploitation five days later and to date have identified 361 compromised vCenter IPs across 47 countries. Broadcom confirms no workaround is available and patching is the only remediation.

Critical severity. Act immediately.

Summary

Critical directory-traversal vulnerability in the VMware vCenter Server Syslog service. An unauthenticated attacker with network access to vCenter can execute arbitrary code on the appliance. Broadcom disclosed the flaw in VMSA-2026-0006 on 29 July 2026; incident responders at QUIRSO GmbH observed in-the-wild exploitation five days later and to date have identified 361 compromised vCenter IPs across 47 countries. Broadcom confirms no workaround is available and patching is the only remediation.

Impact

Exploitability signals: CVSS 9.8 · active exploitation in the wild attributed to a suspected APT actor · post-exploitation deployment of the reverse_ssh framework for persistent remote access on every observed victim.

vCenter Server is the management plane for a vSphere environment. Successful exploitation gives an intruder a foothold from which to reach connected ESXi hosts, hosted workloads, stored credentials, and administrative operations across the virtualised estate.

Affected systems

  • vCenter 9.1 — fixed in 9.1.0.0300
  • vCenter 9.0 — fixed in 9.0.2.0100
  • vCenter 8.0 — fixed in 8.0 U3k or 8.0 U2f, depending on the deployed branch

Action

  1. Patch now. Apply the vendor-provided fix identified in Broadcom VMSA-2026-0006.1 for your deployed branch. No workaround exists.
  2. Reduce exposure. vCenter management interfaces (UI, API, Syslog service) should not be reachable from the public internet. Place them behind institutional firewalls or a management VLAN and require VPN for administrative access.
  3. Hunt for post-exploitation activity. Look for the reverse_ssh persistence mechanism on vCenter appliances: unexpected outbound SSH sessions, binaries in non-standard paths, and processes matching QUIRSO’s published YARA rule. Treat any match as an investigative lead and correlate with other signs of compromise.
  4. Assume compromise if exposed and unpatched since 3 August 2026. If your vCenter has been internet-reachable during that window, engage full incident response rather than relying on the patch alone.
  5. GARNET CSIRT is monitoring the Shadowserver Special Report covering victims of this campaign (report prefix 2026-08-13-special). Any member-institution IPs appearing in the feed will be notified directly. Institutions that operate vCenter and suspect compromise should report an incident.
§ Verify this advisory✓ PGP-signed

This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:

$ curl -O https://csirt.garnet.edu.gh/advisories/2026-003-vmware-vcenter-server-remote-code-execution-vulnerability-ac.md
$ curl -O https://csirt.garnet.edu.gh/advisories/2026-003-vmware-vcenter-server-remote-code-execution-vulnerability-ac.md.asc
$ gpg --import garnet-csirt.asc
$ gpg --verify 2026-003-vmware-vcenter-server-remote-code-execution-vulnerability-ac.md.asc 2026-003-vmware-vcenter-server-remote-code-execution-vulnerability-ac.md

Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.


Think a system in the community is affected or compromised?Report an incident