CISA: Critical VMware RCE flaw now exploited by ransomware gangs
Recorded: Sept. 15, 2026, 2:46 p.m.
| Original | Summarized |
CISA: Critical VMware RCE flaw now exploited by ransomware gangs News Featured Hackers hijack HBO Max Reddit account to push malware in ClickFix ads Homebrew 7.0.0 gets built-in GUI, better security controls Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent New Android malware encrypts files, steals data, and harasses victims Hackers target WordPress sites via third-party WooCommerce plugin What Zero-Day Response Should Be in the Post-Mythos Era CISA: Critical VMware RCE flaw now exploited by ransomware gangs This lifetime stock-picking subscription is $68.99 (reg. $486) Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityCISA: Critical VMware RCE flaw now exploited by ransomware gangs CISA: Critical VMware RCE flaw now exploited by ransomware gangs By Sergiu Gatlan September 15, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Actively Exploited Sergiu Gatlan Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft releases emergency Windows updates to fix RDS failures Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Microsoft: September updates cause RDS failures on Windows Server Sponsor Posts Patch automation needs more than speed. Action1 brings control into every stage of deployment. Watch a working exploit hit live controls and see exactly what blocks, detects, or misses Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Overdue a password health-check? Audit your Active Directory for free Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) alerted security teams that ransomware gangs are actively exploiting a critical vulnerability in VMware vCenter that had previously been patched in July. The specific vulnerability, tracked as CVE-2026-59310, involves a directory traversal flaw in the vCenter Syslog server, which allows unauthenticated attackers to execute arbitrary code. Broadcom addressed this security gap while simultaneously advising customers that fixing the flaw was an emergency, urging immediate installation of patches. Following this disclosure, digital forensics and incident response company QUIRSO reported that suspected advanced persistent threat actors began exploiting this vulnerability to deploy a reverse SSH tool for establishing persistence and remote access across over 361 IP addresses in 47 countries. In response to this threat, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities Catalog and directed government agencies to secure their vCenter systems within three days. Subsequently, CISA updated its catalog to flag the vulnerability as currently being abused by ransomware gangs. The targeting of VMware infrastructure by these malicious groups is significant because compromised vCenter or ESXi servers provide potential access to an organization's internal network and sensitive data. In addition to this specific vulnerability, historical data indicates a broader pattern of exploitation. Ransomware groups have developed dedicated encryptors specifically designed to target VMware virtual machines, which are now commonly used by enterprises for managing and storing corporate data. Furthermore, CISA has flagged other VMware flaws as being exploited in attacks, including a sandbox escape vulnerability in VMware ESXi (CVE-2025-22225), which has been targeted by Chinese-speaking threat actors since at least February 2024. In the first half of the year, the agency also noted exploitation activity related to flaws in VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) during February and March. Over the span of the last five years, CISA has tagged twenty-six VMware vulnerabilities as exploited in the wild, nine of which were specifically abused by ransomware operations, highlighting a sustained and escalating threat against this virtualization platform. |