Ransomware Groups Have Exploited VMware vCenter Flaw
Attackers are leveraging a critical directory traversal vulnerability to gain persistence within virtualized infrastructures.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust the security of the virtual software platforms used by your organization?
CISA has confirmed that ransomware actors are actively weaponizing CVE-2026-59310, a critical vulnerability in VMware vCenter. This flaw, which allows for unauthenticated arbitrary code execution, has already resulted in the compromise of 361 IP addresses across 47 countries.
Why it matters
Compromising virtualization platforms provides attackers with a single point of failure to seize control over an entire organization's virtual infrastructure. This campaign highlights the high-value target profile that hypervisors represent for persistent access and ransomware deployment.
The vulnerability involves a directory traversal—a flaw allowing attackers to access files outside the restricted root directory—in the vCenter Syslog server. While 26 VMware vulnerabilities have been exploited over the past five years, nine are now officially linked to active ransomware campaigns.
The players
CISA
The Cybersecurity and Infrastructure Security Agency is the lead U.S. federal agency responsible for mitigating systemic risk to national critical infrastructure.
Broadcom
A global technology company that manages the VMware software portfolio and oversees its enterprise security updates and infrastructure lifecycle.
The details
Attackers exploit CVE-2026-59310 to achieve unauthenticated arbitrary code execution on target systems. By traversing restricted directory structures, they gain the ability to install reverse SSH tools—a method of creating an outbound connection that allows persistent, unauthorized remote access to the internal network. This architecture allows them to bypass traditional perimeters and entrench themselves within the victim's virtualized environment.
Timeline
July 29, 2026: Broadcom released a patch for the vCenter Syslog server vulnerability.
August 2026: CISA officially added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog.
September 2026: CISA confirmed that ransomware groups are actively exploiting the flaw.
The Tech Race
This activity follows the established enforcement pattern for the CISA Known Exploited Vulnerabilities catalog. The inclusion of this flaw triggers mandatory remediation mandates for federal agencies to contain the threat within the competitive race for virtual environment dominance.
IT administrators should verify that all vCenter instances are updated to the patches released by Broadcom on July 29, 2026. Because the vulnerability allows unauthenticated access, any server still exposed to the public internet is at immediate risk of persistent compromise.
The takeaway
Virtualization security is now a primary front in ransomware operations due to the administrative control it grants attackers. Administrators must monitor the CISA Known Exploited Vulnerabilities catalog for future updates regarding this campaign.
Further reading
For more background on threat mitigation and infrastructure hardening, visit our Cybersecurity section.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you trust the security of the virtual software platforms used by your organization?






