Affected Systems
VMware vCenter Server versions prior to 9.1.0.0300 (9.1 branch), 9.0.2.0100 (9.0 branch), and 8.0 U3k/U2f (8.0 branch). The vulnerability affects the vCenter Syslog Server component and is exploitable by unauthenticated attackers with network access.
Exploitation Status
Active exploitation confirmed. Campaign began August 3, 2026, five days after patch release. 361 compromised IP addresses identified across 47 countries by August 7. Attackers deploy reverse_ssh framework for persistence and C2. Suspected APT activity.
Business Impact
VMware vCenter provides centralized control over virtual infrastructure including ESXi hosts, VMs, and access permissions. Successful exploitation grants unauthenticated remote code execution, enabling attackers to establish persistent access, bypass network security controls via outbound SSH tunnels, and pivot to managed virtual environments. High risk of data theft, operational disruption, and lateral movement across virtualized infrastructure.
Urgency
🔴 Immediate
Recommended Actions
- Immediately patch vCenter to version 9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f depending on branch—no workarounds available
- Hunt for reverse_ssh binaries on vCenter systems using QUIRSO's published YARA rule and check for unexpected outbound SSH connections
- Review vCenter Syslog Server logs from August 3 onward for unauthorized access attempts or directory traversal patterns
- Isolate unpatched vCenter instances from network access until patching is complete, prioritizing internet-facing systems
- Audit vCenter user accounts and recent configuration changes for signs of unauthorized persistence mechanisms or credential theft
