CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/

ONE SENTENCE SUMMARY:

CISA warns ransomware gangs are exploiting critical VMware vCenter CVE-2026-59310, urging urgent patching amid widespread global compromises online now detected.

MAIN POINTS:

  1. Broadcom patched CVE-2026-59310 in vCenter Syslog on July 29.
  2. Vulnerability is a critical directory traversal enabling unauthenticated remote code execution.
  3. Supplemental FAQ urged customers to treat remediation as an emergency.
  4. QUIRSO observed APT exploitation deploying a reverse SSH tool for persistence.
  5. Investigators found 361 compromised IPs spanning 47 countries after initial exploitation.
  6. CISA added the flaw to KEV and mandated federal remediation within three days.
  7. KEV entry was later updated, noting active abuse by ransomware groups.
  8. Shadowserver reports over 450 vCenter servers currently exposed to the internet.
  9. Attackers favor vCenter/ESXi compromise for lateral access to networks and sensitive data.
  10. CISA has tagged 26 VMware flaws exploited in five years; nine linked to ransomware.

TAKEAWAYS:

  1. Apply vCenter patches immediately when KEV-listed, especially for unauthenticated RCE conditions.
  2. Reduce internet exposure of vCenter services to shrink attack surface and opportunistic scanning.
  3. Hunt for reverse SSH backdoors and unusual persistence following vCenter compromise indicators.
  4. Expect ransomware operators to target VMware ecosystems using purpose-built VM encryptors.
  5. Track CISA KEV updates to prioritize remediation ahead of rapid threat-actor adoption.