Skip to content
Security

CISA warns VMware vCenter vulnerability is being used in ransomware attacks

CISA on Tuesday added a critical VMware vCenter flaw to its catalog of known exploited vulnerabilities, noting that ransomware gangs are now actively using it. The agency flagged CVE-2026-59310 as being abused in ransomware campaigns, according to a CISA alert.

Matthew Eveland

1 minute read

Security: Office Work
Photo: Negative Space (CC0-1.0) via Openverse

CISA on Tuesday added a critical VMware vCenter flaw to its catalog of known exploited vulnerabilities, noting that ransomware gangs are now actively using it. The agency flagged CVE-2026-59310 as being abused in ransomware campaigns, according to a CISA alert.

Broadcom patched this critical directory traversal flaw in the vCenter Syslog server on July 29. It allows unauthenticated attackers to execute arbitrary code, according to Broadcom’s security advisory.

Digital forensics firm QUIRSO found over 361 compromised IP addresses across 47 countries exploiting the flaw to deploy remote access tools. Internet monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online, though it’s unclear how many are patched.

If you run a dental office, law firm, or restaurant that uses VMware vCenter to manage its servers or store corporate data, this is your alert. You need to verify that your vCenter Syslog server is patched against CVE-2026-59310 immediately. Broadcom treats fixing this as an emergency.

Here’s the thing: VMware servers are common targets because they hold the keys to your network. CISA previously ordered government agencies to secure their systems within three days of adding the flaw to its catalog. We don’t have that federal deadline, but the risk is real. Check your patch status today. Don’t wait for Monday.

Sources: BleepingComputer.

Advertisement — 30th West Technology Solutions

30th West Technology Solutions

IT support for Antelope Valley businesses

When you call, you talk to an owner — not a call center.

Veteran-owned · Rosamond · English & Spanish

See what we do

Written by

Matthew Eveland

Matthew Eveland writes SMB Tech News, a weekly read on the security, software and scam news that actually reaches small businesses.

Security