Ransomware Gangs Now Exploiting Critical VMware vCenter Flaw, CISA Warns
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that ransomware gangs have joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. Broadcom fixed the flaw, tracked as CVE-2026-59310, on July 29, describing it as a directory traversal vulnerability in the vCenter Syslog server that allows unauthenticated attackers to execute arbitrary code. The company urges customers to treat patching as an emergency.
Shortly after the patch's release, digital forensics firm QUIRSO reports finding over 361 compromised IP addresses across 47 countries, linking the attacks to a suspected advanced persistent threat actor deploying a reverse SSH tool for persistence and remote access. CISA has since added the vulnerability to its Known Exploited Vulnerabilities Catalog and orders government agencies to secure their vCenter systems within three days. Security monitor Shadowserver currently tracks more than 450 VMware vCenter servers exposed online, though the number already patched remains unknown.
Ransomware gangs increasingly target VMware infrastructure because compromised vCenter or ESXi servers provide access to corporate networks and sensitive data. Multiple ransomware groups have developed dedicated encryptors aimed at VMware virtual machines, which enterprises commonly use to manage and store data. CISA has also flagged other VMware flaws this year, including an ESXi sandbox escape vulnerability exploited by Chinese-speaking threat actors since early 2024.