Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

CISA: Ransomware gangs exploit critical VMware vCenter flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says ransomware gangs have joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched by Broadcom on July 29.

Tracked as CVE-2026-59310, the flaw affects the vCenter Syslog server. Unauthenticated attackers can exploit it to execute arbitrary code. Broadcom urged customers to treat remediation as an emergency.

Two weeks later, digital forensics company QUIRSO reported more than 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat actor exploited the flaw to deploy a reverse SSH tool for persistence and remote access. CISA later added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and gave government agencies three days to secure their vCenter systems.

Over the weekend, CISA updated the catalog to say ransomware gangs were actively abusing the vulnerability. Shadowserver currently tracks more than 450 VMware vCenter servers exposed online, although it is unknown how many have been patched.

CISA has not shared details about ransomware attacks targeting CVE-2025-60710. Over the last five years, it has identified 26 VMware vulnerabilities exploited in the wild, including nine also used by ransomware operations. It also reported exploitation of CVE-2025-22225 since at least February 2024, CVE-2026-22719 in February, and CVE-2024-37079 in March.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.