CISA: Critical VMware RCE flaw now exploited by ransomware gangs

A Critical Vulnerability in VMware vCenter is Being Exploited by Ransomware Gangs, Warns CISA

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to security teams that ransomware gangs have joined ongoing attacks exploiting a critical vulnerability in VMware’s vCenter server. This highly sought-after exploit was patched in July, but it appears that many organizations have yet to apply the fix.

For those unfamiliar with the technical details, the vulnerability (tracked as CVE-2026-59310) is a directory traversal flaw in the vCenter Syslog server. Essentially, this means that an attacker can execute arbitrary code on an unpatched system without needing any authentication or credentials. This kind of access can grant a malicious actor unfettered control over an organization’s network and sensitive data.

The situation has been dire since July, when Broadcom patched the flaw and urged customers to treat it as an emergency, installing patches as soon as possible. However, recent updates from CISA indicate that ransomware gangs have now jumped into the fray, exploiting this vulnerability to deploy malicious tools for persistence and remote access. This is a worrying trend, given the devastating impact of ransomware attacks on organizations worldwide.

VMware vCenter servers are prime targets for attackers due to their role in managing and storing corporate data. In recent years, multiple ransomware gangs have developed dedicated encryptors specifically designed to target VMware virtual machines. CISA has been tracking this trend closely, warning that ransomware groups began exploiting a related vulnerability (CVE-2025-22225) as far back as February 2024.

Since the start of this year alone, CISA has flagged several other critical vulnerabilities in VMware products, including VMware Aria Operations and vCenter Server. Over the last five years, the agency has identified a staggering 26 exploited VMware vulnerabilities, nine of which were abused by ransomware operations.

So what can organizations do to protect themselves? The takeaway is clear: patching is not optional. If you’re running an unpatched version of vCenter server, it’s imperative that you apply the latest updates immediately. Additionally, be aware of the potential for lateral movement and data exfiltration if your VMware environment has been compromised. Conduct thorough risk assessments to identify any vulnerabilities in your systems and prioritize remediation accordingly.

In conclusion, this vulnerability serves as a stark reminder of the ongoing threat posed by ransomware gangs and the importance of timely patching. Don’t wait until it’s too late – take proactive steps today to secure your VMware environment against potential threats.


Source: Bleeping Computer — 2026-09-15