rootpwn

Threat Intel

Ransomware Gangs Exploit Critical VMware vCenter RCE (CVE‑2026‑59310) – CISA Urges Urgent Patching

CISA has flagged the July‑patched VMware vCenter flaw CVE‑2026‑59310 as actively abused by ransomware operators. The directory‑traversal bug in the vCenter Syslog server lets unauthenticated attackers run arbitrary code, enabling reverse‑SSH back‑doors and data exfiltration. Over 450 exposed vCenter instances and more than 360 compromised IPs across 47 countries have been identified. CISA now demands all federal agencies secure their vCenter deployments within three days and urges private sector customers to apply the patch immediately.

VMware’s vCenter Server has become a prime target for ransomware crews, and the latest wave of attacks is exploiting a flaw that was patched in late July. The vulnerability, tracked as CVE‑2026‑59310, allows an unauthenticated attacker to traverse directories on the vCenter Syslog server and execute arbitrary code. Broadcom described it as “critical” and urged customers to treat the fix as an emergency.

What’s at Stake

  • Unauthenticated remote code execution on vCenter servers.
  • Potential deployment of reverse‑SSH tools for persistence.
  • Access to corporate networks and sensitive data stored in virtual machines.

How the Exploit Works

The flaw lies in the Syslog component of vCenter. An attacker can send a crafted request that causes the server to read files outside the intended directory, leading to code execution. Once compromised, the attacker can install back‑doors, exfiltrate data, or pivot to other systems.

Current Impact

  • Over 450 vCenter servers are publicly exposed, according to Shadowserver.
  • QUIRSO identified 361 compromised IP addresses in 47 countries linked to the vulnerability.
  • Ransomware groups are using the back‑door to deploy their encryptors and demand ransoms.

CISA Guidance

“The U.S. Cybersecurity and Infrastructure Security Agency has added CVE‑2026‑59310 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days.”

Private‑sector customers are also urged to apply the July patch immediately and conduct a full inventory of vCenter deployments. CISA’s latest advisory stresses that ransomware operators have been targeting VMware environments for years, with previous exploits such as CVE‑2025‑22225 and CVE‑2026‑22719 already in the wild.

Broader VMware Threat Landscape

  • Multiple VMware flaws have been actively exploited in the past year.
  • Ransomware groups have developed dedicated encryptors for virtual machines.
  • Ongoing vigilance is required as new zero‑day vulnerabilities surface.

Defenders should prioritize patch management, monitor for unusual Syslog activity, and isolate vulnerable vCenter instances until the fix is applied.

VMware Ransomware CISA vCenter Remote Code Execution Patch Management

← All news