CISA Warns Ransomware Groups Are Exploiting Critical VMware vCenter Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned security teams that ransomware groups are actively exploiting a critical vulnerability in VMware vCenter that was patched in July.
Broadcom addressed the flaw, tracked as CVE-2026-59310, on July 29. The vulnerability is a critical directory traversal flaw in vCenter Syslog Server that could allow an unauthenticated attacker to execute arbitrary code.
Broadcom also urged customers to treat the CVE-2026-59310 fix as an emergency and install the patch as soon as possible. The company published a supplemental FAQ with additional information.
Two weeks later, digital forensics and incident response (DFIR) firm QUIRSO reported that more than 361 IP addresses across 47 countries had been compromised. Suspected advanced persistent threat (APT) attackers were reportedly exploiting vulnerabilities to deploy reverse SSH tools for persistence and remote access.
A few days later, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog. The agency ordered government organizations to secure affected vCenter systems within three days.
Over the weekend, CISA updated the KEV catalog again and reported that the vulnerability is actively exploited by ransomware gangs.
Internet security threat monitor Shadowserver is currently tracking more than 450 VMware vCenter servers online. However, there is no information about how many organizations have already patched the vulnerability.
Why ransomware groups target VMware vCenter
U.S. cybersecurity agencies have not yet released details about the ransomware attacks exploiting CVE-2026-59310. However, VMware servers are common targets because compromised vCenter or ESXi systems can provide access to sensitive data and other systems on an organization’s network.
As organizations increasingly use VMware virtual machines to manage and store corporate data, several ransomware gangs have developed specialized encryption tools designed to target VMware virtual machines.
CISA also warned in February that ransomware groups had begun exploiting the VMware ESXi sandbox escape vulnerability CVE-2025-22225. Chinese-speaking attackers have reportedly targeted the vulnerability in zero-day attacks since at least February 2024.
Since the beginning of this year, cybersecurity agencies have reported attacks exploiting flaws in VMware Aria Operations, including CVE-2026-22719, and VMware vCenter Server, including CVE-2024-37079.
Over the past five years, CISA has listed 26 VMware vulnerabilities in its KEV Catalog. Nine of those vulnerabilities were also exploited by ransomware operations.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



