Skip to content
Tech News
← Back to articles

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

read original more articles
Why This Matters

This story highlights a critical cybersecurity vulnerability in VMware vCenter that has been actively exploited by ransomware gangs, emphasizing the importance of timely patching and security vigilance for organizations. It underscores how cybercriminals are increasingly targeting enterprise infrastructure to gain access and deploy ransomware, posing significant risks to data security and operational continuity.

Key Takeaways

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.

Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.

The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.

Two weeks later, digital forensics and incident response (DFIR) company QUIRSO reported finding over 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat (APT) actor began exploiting the vulnerability to deploy a reverse SSH tool for persistence and remote access.

Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days.

Over the weekend, CISA updated its KEV catalog again to flag the security vulnerability as actively abused by ransomware gangs.

Internet security threat monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online; however, there is no information on how many have already been patched against this flaw.

VMware targeted by ransomware gangs

While the U.S. cybersecurity agency has yet to share any details about the ransomware attacks targeting CVE-2025-60710, VMware servers are commonly targeted because compromised vCenter or ESXi servers can provide access to an organization's network and sensitive data stored on internal systems.

In recent years, multiple ransomware gangs have developed dedicated encryptors to target VMware virtual machines, as enterprise organizations now commonly use them to manage and store corporate data.

... continue reading