VMware logo representing the critical vCenter vulnerability Original image source: bleepstatic.com



The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that ransomware gangs are now actively exploiting a critical VMware vCenter vulnerability, identified as CVE-2026-59310, which was patched in July. This development comes after an initial wave of attacks suspected to be from advanced persistent threat (APT) actors.



Detalles de la Vulnerabilidad y su Explotación

Broadcom, the company behind VMware, addressed CVE-2026-59310 on July 29, classifying it as a critical directory traversal flaw within the vCenter Syslog server. This vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems. At the time of the patch release, Broadcom urged customers to prioritize its remediation, emphasizing the urgency of applying updates.



Just two weeks post-patch, the digital forensics and incident response firm QUIRSO reported a significant number of compromises. Their findings indicated over 361 IP addresses across 47 countries were affected, with a suspected APT actor leveraging the vulnerability to deploy a reverse SSH tool for persistent access and remote control.



CISA quickly added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog, mandating U.S. government agencies to secure their vCenter systems within a tight three-day window. More recently, CISA updated its KEV catalog entry for the flaw, specifically flagging its active abuse by ransomware gangs.



¿Por qué VMware es un Objetivo?

VMware servers, particularly vCenter and ESXi, are attractive targets for threat actors because compromising them can grant extensive access to an organization’s network and sensitive data. Ransomware groups have increasingly developed specialized encryptors designed to target VMware virtual machines, which are widely used by enterprises for managing and storing corporate information.



Internet security threat monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online, though the exact number patched against this specific flaw remains unknown.



Historial de Vulnerabilidades de VMware Explotadas

This is not an isolated incident for VMware. CISA has previously highlighted other VMware vulnerabilities being exploited in the wild:

  • CVE-2025-22225 (VMware ESXi sandbox escape): Exploited by Chinese-speaking threat actors in zero-day attacks since at least February 2024.
  • CVE-2026-22719 (VMware Aria Operations): Flagged as exploited in February.
  • CVE-2024-37079 (VMware vCenter Server): Flagged as exploited in March.

Over the last five years, CISA has identified 26 VMware vulnerabilities as exploited in real-world attacks, with nine of these also being abused by ransomware operations.



Conclusión

The escalating exploitation of CVE-2026-59310 by ransomware gangs underscores the critical importance of timely patching and robust security practices for VMware environments. Organizations running vCenter servers are urged to immediately verify that all necessary patches are applied to mitigate the risk of severe operational disruption and data exfiltration at the hands of ransomware actors. The continuous targeting of VMware platforms by various sophisticated threat actors highlights the need for constant vigilance and proactive threat hunting within enterprise networks.



Referencias

Original source: View original article

  • CVE-2026-59310
  • CVE-2025-22225
  • CVE-2026-22719
  • CVE-2024-37079
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog