CVE-2026-59310
CRITICAL(9.8)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS 9.8 — Kritisch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
2.6%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
SecBoard-Einordnung
CVE-2026-59310 betrifft VMware vCenter Server und ist eine Directory Traversal Schwachstelle im Syslog-Server. Ein Angreifer mit Netzwerkzugriff auf vCenter kann diese Schwachstelle ausnutzen, um beliebigen Code auszuführen. Die erfolgreiche Ausnutzung führt zu einer vollständigen Kompromittierung des Systems.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Erkennung & Indikatoren
Ausnutzung
Aktiv ausgenutzt (CISA KEV). Angreifer haben die Schwachstelle seit dem 3. August 2026 ausgenutzt, um ein Open-Source-SSH-Reverse-Shell-Framework zu installieren. Später wurde beobachtet, dass Ransomware-Gangs die Schwachstelle aktiv ausnutzen. Ein mutmaßlicher APT-Akteur mit China-Bezug soll die Schwachstelle ausgenutzt haben, um eine Backdoor zusammen mit reverse_ssh-Binärdateien für persistente
Behobene Versionen
- 9.1.0.0300
Threat-Hunting-Queries
Die Schwachstelle ist eine Directory Traversal in vCenter Syslog. Suchen Sie nach ungewöhnlichen Dateierstellungs- oder -modifikationsereignissen im Syslog-Verzeichnis oder nach Prozessen, die vom Syslog-Server gestartet werden und nicht dem normalen Verhalten entsprechen. Insbesondere die Bereitstellung von Reverse-SSH-Tools oder Ransomware-Binärdateien ist ein starker Indikator.
Sentinel/Defender KQL
DeviceProcessEvents
| where InitiatingProcessFileName =~ "syslogd" or FileName =~ "syslogd" // Adjust based on actual syslog process name
| where ProcessCommandLine has_any ("ssh", "reverse_shell", "ransomware", "babuk") or FolderPath contains "syslog" and (ProcessCommandLine has_any ("powershell", "cmd.exe", "sh", "bash")) // Look for suspicious commands or shell activity originating from or targeting syslog related paths
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, FolderPath, SHA256Splunk SPL
(sourcetype="syslog" OR sourcetype="vmware:vcenter:log") (syslogd OR "syslog server") (ssh OR reverse_shell OR ransomware OR babuk OR powershell OR cmd.exe OR sh OR bash)
| table _time, host, source, _raw
| search _raw IN (*ssh*, *reverse_shell*, *ransomware*, *babuk*) OR (_raw IN (*syslog*) AND _raw IN (*powershell*, *cmd.exe*, *sh*, *bash*))Sigma
title: VMware vCenter Syslog Directory Traversal Exploitation
id: 00000000-0000-0000-0000-000000000000
status: experimental
description: Detects potential exploitation of CVE-2026-59310 in VMware vCenter Syslog server.
author: SecBoard
date: 2026/09/17
logsource:
product: linux
service: syslog
detection:
selection:
ParentImage|endswith: 'syslogd'
CommandLine|contains:
- 'ssh'
- 'reverse_shell'
- 'ransomware'
- 'babuk'
- 'powershell'
- 'cmd.exe'
- 'sh'
- 'bash'
condition: selection
level: criticalElastic ES|QL
from process where process.parent.name == "syslogd" and (process.command_line : ("ssh", "reverse_shell", "ransomware", "babuk") or (process.command_line : ("powershell", "cmd.exe", "sh", "bash") and process.working_directory : "*syslog*"))SecBoard-generated · behavioral · requires customization — Von SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.
Ausgewertete Quellen
- https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html
- https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
- https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html
- https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
- https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-microsoft-vmware-apple-vulnerabilities/
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Betroffene Produkte
- cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:-:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update1e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update2e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:8.0:update3b:*:*:*:*:*:*
In diesen Analysen erwähnt
Referenzen
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/con...
- https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-i...
- https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-...