CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Cybersecurity experts are on high alert as the US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in VMware’s vCenter Server, patched just two months ago, is now being actively exploited by ransomware gangs. The agency warns that these groups have joined other attackers in using this flaw to gain unauthorized access to sensitive data stored on enterprise networks.

The vulnerability, tracked as CVE-2026-59310, was identified by Broadcom in July and described as a critical directory traversal issue that allows unauthenticated attackers to execute arbitrary code on the vCenter Syslog server. The company emphasized the need for immediate action, advising customers to treat fixing this flaw as an emergency and install patches as soon as possible.

However, it appears that many organizations have yet to take necessary precautions. According to the threat monitoring service Shadowserver, over 450 VMware vCenter servers remain exposed online, leaving them vulnerable to exploitation. While there is no information on how many of these systems have already been patched, CISA has ordered government agencies to secure their vCenter installations within three days.

VMware’s reputation as a target-rich environment for attackers is well-documented. Ransomware gangs frequently develop dedicated encryptors to target VMware virtual machines, which are commonly used by enterprises to manage and store sensitive corporate data. Furthermore, multiple vulnerabilities in VMware products have been exploited in recent attacks, including a sandbox escape vulnerability that Chinese-speaking threat actors targeted with zero-day exploits as far back as 2024.

The fact that ransomware gangs are now actively exploiting this flaw is particularly concerning, given the potential for catastrophic consequences. If an attacker gains access to a vCenter Server, they can use it as a springboard to compromise other systems on the network, stealing sensitive data or holding it hostage for ransom.

For organizations still running unpatched VMware systems, time is of the essence. CISA’s warning should serve as a wake-up call to prioritize patching and securing these installations immediately. In doing so, they can minimize their exposure to this and other known vulnerabilities, preventing potential attacks from turning into costly security breaches.


Source: Bleeping Computer — 2026-09-15