VMware vCenter systems are being actively compromised through the critical CVE-2026-59310 path-traversal flaw, with 361 victim IP addresses identified across 47 countries. Attackers are installing cron jobs, SSH keys, and the reverse_ssh tool to maintain access after exploiting the vCenter Syslog Server.
Source