Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
ONE SENTENCE SUMMARY:
CISA warns ransomware gangs are exploiting critical VMware vCenter CVE-2026-59310, urging urgent patching amid widespread global compromises online now detected.
MAIN POINTS:
- Broadcom patched CVE-2026-59310 in vCenter Syslog on July 29.
- Vulnerability is a critical directory traversal enabling unauthenticated remote code execution.
- Supplemental FAQ urged customers to treat remediation as an emergency.
- QUIRSO observed APT exploitation deploying a reverse SSH tool for persistence.
- Investigators found 361 compromised IPs spanning 47 countries after initial exploitation.
- CISA added the flaw to KEV and mandated federal remediation within three days.
- KEV entry was later updated, noting active abuse by ransomware groups.
- Shadowserver reports over 450 vCenter servers currently exposed to the internet.
- Attackers favor vCenter/ESXi compromise for lateral access to networks and sensitive data.
- CISA has tagged 26 VMware flaws exploited in five years; nine linked to ransomware.
TAKEAWAYS:
- Apply vCenter patches immediately when KEV-listed, especially for unauthenticated RCE conditions.
- Reduce internet exposure of vCenter services to shrink attack surface and opportunistic scanning.
- Hunt for reverse SSH backdoors and unusual persistence following vCenter compromise indicators.
- Expect ransomware operators to target VMware ecosystems using purpose-built VM encryptors.
- Track CISA KEV updates to prioritize remediation ahead of rapid threat-actor adoption.