Ransomware Groups Have Exploited VMware vCenter Flaw

Attackers are leveraging a critical directory traversal vulnerability to gain persistence within virtualized infrastructures.

Updated on Sept. 27, 2026 in Cybersecurity

Bold flat-color editorial illustration of a geometric server module in navy and cream, signifying infrastructure vulnerability.
CISA has confirmed that ransomware groups are weaponizing a critical flaw in VMware vCenter, impacting hundreds of IP addresses globally. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of the virtual software platforms used by your organization?

CISA has confirmed that ransomware actors are actively weaponizing CVE-2026-59310, a critical vulnerability in VMware vCenter. This flaw, which allows for unauthenticated arbitrary code execution, has already resulted in the compromise of 361 IP addresses across 47 countries.

Why it matters

Compromising virtualization platforms provides attackers with a single point of failure to seize control over an entire organization's virtual infrastructure. This campaign highlights the high-value target profile that hypervisors represent for persistent access and ransomware deployment.

The vulnerability involves a directory traversal—a flaw allowing attackers to access files outside the restricted root directory—in the vCenter Syslog server. While 26 VMware vulnerabilities have been exploited over the past five years, nine are now officially linked to active ransomware campaigns.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is the lead U.S. federal agency responsible for mitigating systemic risk to national critical infrastructure.

Broadcom

A global technology company that manages the VMware software portfolio and oversees its enterprise security updates and infrastructure lifecycle.

The details

Attackers exploit CVE-2026-59310 to achieve unauthenticated arbitrary code execution on target systems. By traversing restricted directory structures, they gain the ability to install reverse SSH tools—a method of creating an outbound connection that allows persistent, unauthorized remote access to the internal network. This architecture allows them to bypass traditional perimeters and entrench themselves within the victim's virtualized environment.

Timeline

  1. July 29, 2026: Broadcom released a patch for the vCenter Syslog server vulnerability.

  2. August 2026: CISA officially added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog.

  3. September 2026: CISA confirmed that ransomware groups are actively exploiting the flaw.

The Tech Race

This activity follows the established enforcement pattern for the CISA Known Exploited Vulnerabilities catalog. The inclusion of this flaw triggers mandatory remediation mandates for federal agencies to contain the threat within the competitive race for virtual environment dominance.

IT administrators should verify that all vCenter instances are updated to the patches released by Broadcom on July 29, 2026. Because the vulnerability allows unauthenticated access, any server still exposed to the public internet is at immediate risk of persistent compromise.

The takeaway

Virtualization security is now a primary front in ransomware operations due to the administrative control it grants attackers. Administrators must monitor the CISA Known Exploited Vulnerabilities catalog for future updates regarding this campaign.

Further reading

For more background on threat mitigation and infrastructure hardening, visit our Cybersecurity section.

Source note: This article includes information reported by Computer Crime Research Center.

Live Poll

Do you trust the security of the virtual software platforms used by your organization?