CISA says ransomware gangs are now exploiting CVE-2026-59310, a critical VMware vCenter flaw that allows unauthenticated remote code execution.

CISA Warns Ransomware Gangs Are Exploiting Critical VMware vCenter Flaw

The420 Web Correspondent
6 Min Read

Ransomware gangs are now exploiting a critical VMware vCenter Server vulnerability that can let unauthenticated attackers execute code remotely, prompting a fresh warning from the US Cybersecurity and Infrastructure Security Agency.

The flaw, tracked as CVE-2026-59310, carries a severity score of 9.8 out of 10 and affects the Syslog server component in VMware vCenter.

Broadcom patched it on July 29, but the vulnerability was weaponised within days and has since been used in attacks across multiple countries.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Attackers can execute code without logging in

The vulnerability is a directory-traversal flaw in the vCenter Syslog server.

Broadcom says an attacker with network access to the vulnerable server can exploit it to execute arbitrary code, without needing valid credentials.

That makes the flaw especially serious because vCenter is not an ordinary application server.

It acts as the management layer for VMware environments, allowing administrators to control ESXi hosts and virtual machines from one place.

If attackers gain control of vCenter, they may be able to move deeper into the virtual infrastructure rather than compromising only one system.

Ransomware operators have now entered the attack chain

CISA first added CVE-2026-59310 to its Known Exploited Vulnerabilities catalogue after active exploitation was confirmed.

It has now updated that entry to indicate known ransomware use.

BleepingComputer reports that CISA has not yet publicly identified the ransomware groups involved in the latest attacks.

However, the flaw had already been linked to a suspected China-nexus threat actor.

Incident-response firm QUIRSO reported that attackers began exploiting CVE-2026-59310 within five days of Broadcom releasing the patch, compromising more than 361 IP addresses across 47 countries.

Researchers observed the attackers installing reverse-SSH tools for persistence and creating additional access mechanisms inside compromised environments.

In at least some cases, Babuk-derived ransomware was later deployed against ESXi systems.

Why vCenter is such a high-value ransomware target

A normal ransomware attack may begin by compromising an employee account or workstation.

vCenter offers a much more powerful starting point.

An organisation may run dozens or hundreds of virtual servers under one VMware environment.

Those machines could contain databases, business applications, file servers and other critical systems.

If attackers compromise the management layer, they may gain a route towards many of those machines at once.

This is why ransomware groups increasingly target virtualisation infrastructure.

Encrypting or shutting down ESXi-hosted virtual machines can disrupt a large part of an organisation in a single attack.

BleepingComputer notes that multiple ransomware operations have developed dedicated tools targeting VMware environments for exactly this reason.

What does remote code execution mean here?

Remote code execution, or RCE, means an attacker may be able to make a vulnerable system run commands of their choosing from another machine.

In this case, the attacker does not need to be sitting at the VMware console or already have an account.

They need network access to the vulnerable vCenter system and a way to reach the affected service.

Once arbitrary code can be executed, attackers may attempt to install backdoors, create accounts, steal credentials or move towards connected ESXi hosts.

That can turn one exposed management server into an entry point for a much larger ransomware incident.

More than 450 vCenter servers still exposed online

The Shadowserver Foundation was tracking more than 450 VMware vCenter servers exposed to the internet when CISA issued its latest warning.

It is not clear how many of those systems had already been patched.

Internet exposure is particularly dangerous because it increases the number of attackers who can attempt to reach the vulnerable service.

But internal exposure can also matter.

An attacker who compromises another system inside a corporate network may later use CVE-2026-59310 to move into vCenter.

Organisations therefore should not assume they are safe simply because their vCenter server is not directly visible from the public internet.

Broadcom says there is no workaround

Broadcom has made clear that there is no configuration workaround for CVE-2026-59310.

The fix is to install the appropriate patched version.

For vCenter 9.1, Broadcom lists version 9.1.0.0300 as fixed.

For version 9.0, the fixed release is 9.0.2.0100.

For vCenter 8.0, fixes are available in 8.0 U3k and 8.0 U2f. Organisations running vCenter 7.0 need to contact Broadcom Support if they have an extended support contract.

Given that ransomware use is now confirmed, organisations that have not patched should treat the issue as an incident-response priority rather than routine maintenance.

Security teams should also investigate for signs of earlier compromise, including unexpected administrator accounts, persistence tools and unusual connections from the vCenter appliance.

What this means for you: This vulnerability mainly affects organisations running VMware vCenter, not ordinary home users. IT teams should patch immediately and check already-exposed systems for signs of compromise instead of assuming that applying the update now automatically removes an attacker who may already be inside.

The420 Insight: The dangerous part of this flaw is not just its 9.8 severity score. vCenter sits above the virtual machines that keep many enterprises running, so a successful compromise can give ransomware operators a route towards an entire cluster rather than a single server.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected