LmCast :: Stay tuned in

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Recorded: Sept. 15, 2026, 2:46 p.m.

Original Summarized

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

News

Featured
Latest

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Homebrew 7.0.0 gets built-in GUI, better security controls

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

New Android malware encrypts files, steals data, and harasses victims

Hackers target WordPress sites via third-party WooCommerce plugin

What Zero-Day Response Should Be in the Post-Mythos Era

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

This lifetime stock-picking subscription is $68.99 (reg. $486)

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityCISA: Critical VMware RCE flaw now exploited by ransomware gangs

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

By Sergiu Gatlan

September 15, 2026
08:16 AM
0

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.
The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.
Two weeks later, digital forensics and incident response (DFIR) company QUIRSO reported finding over 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat (APT) actor began exploiting the vulnerability to deploy a reverse SSH tool for persistence and remote access.
Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days.
Over the weekend, CISA updated its KEV catalog again to flag the security vulnerability as actively abused by ransomware gangs.
Internet security threat monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online; however, there is no information on how many have already been patched against this flaw.
VMware targeted by ransomware gangs
While the U.S. cybersecurity agency has yet to share any details about the ransomware attacks targeting CVE-2025-60710, VMware servers are commonly targeted because compromised vCenter or ESXi servers can provide access to an organization's network and sensitive data stored on internal systems.
In recent years, multiple ransomware gangs have developed dedicated encryptors to target VMware virtual machines, as enterprise organizations now commonly use them to manage and store corporate data.
CISA also warned in February that ransomware groups began exploiting a VMware ESXi sandbox escape vulnerability (CVE-2025-22225), which Chinese-speaking threat actors have targeted in zero-day attacks since at least February 2024.
Since the start of the year, the cybersecurity agency has also flagged VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) flaws as exploited in attacks in February and March.
Over the last five years, CISA has tagged 26 VMware vulnerabilities as exploited in the wild, nine of them also abused by ransomware operations.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
CISA: WatchGuard RCE flaw now exploited in ransomware attacksCISA orders urgent patching of actively exploited Zimbra flawCritical RCE flaw in Windows IKE Extension now actively exploitedCritical VMware vCenter RCE flaw exploited for reverse SSH accessCISA: Microsoft SharePoint flaw now exploited in ransomware attacks

Actively Exploited
CISA
Ransomware
RCE
Remote Code Execution
VMware
VMware vCenter
Warning

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article
Next Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft releases emergency Windows updates to fix RDS failures

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Microsoft: September updates cause RDS failures on Windows Server

Sponsor Posts

Patch automation needs more than speed. Action1 brings control into every stage of deployment.

Watch a working exploit hit live controls and see exactly what blocks, detects, or misses

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) alerted security teams that ransomware gangs are actively exploiting a critical vulnerability in VMware vCenter that had previously been patched in July. The specific vulnerability, tracked as CVE-2026-59310, involves a directory traversal flaw in the vCenter Syslog server, which allows unauthenticated attackers to execute arbitrary code. Broadcom addressed this security gap while simultaneously advising customers that fixing the flaw was an emergency, urging immediate installation of patches. Following this disclosure, digital forensics and incident response company QUIRSO reported that suspected advanced persistent threat actors began exploiting this vulnerability to deploy a reverse SSH tool for establishing persistence and remote access across over 361 IP addresses in 47 countries. In response to this threat, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities Catalog and directed government agencies to secure their vCenter systems within three days. Subsequently, CISA updated its catalog to flag the vulnerability as currently being abused by ransomware gangs.

The targeting of VMware infrastructure by these malicious groups is significant because compromised vCenter or ESXi servers provide potential access to an organization's internal network and sensitive data. In addition to this specific vulnerability, historical data indicates a broader pattern of exploitation. Ransomware groups have developed dedicated encryptors specifically designed to target VMware virtual machines, which are now commonly used by enterprises for managing and storing corporate data. Furthermore, CISA has flagged other VMware flaws as being exploited in attacks, including a sandbox escape vulnerability in VMware ESXi (CVE-2025-22225), which has been targeted by Chinese-speaking threat actors since at least February 2024. In the first half of the year, the agency also noted exploitation activity related to flaws in VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) during February and March. Over the span of the last five years, CISA has tagged twenty-six VMware vulnerabilities as exploited in the wild, nine of which were specifically abused by ransomware operations, highlighting a sustained and escalating threat against this virtualization platform.