<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>VMware on Blog - Comfidentia</title><link>https://blog.comfidentia.cl/en/tags/vmware/</link><description>Recent content in VMware on Blog - Comfidentia</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 15 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.comfidentia.cl/en/tags/vmware/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA Warns Ransomware Gangs Exploiting Critical VMware vCenter Vulnerability</title><link>https://blog.comfidentia.cl/en/2026/09/15/cisa-warns-ransomware-gangs-exploiting-critical-vmware-vcenter-vulnerability/</link><pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate><guid>https://blog.comfidentia.cl/en/2026/09/15/cisa-warns-ransomware-gangs-exploiting-critical-vmware-vcenter-vulnerability/</guid><description>&lt;p&gt;&lt;img alt="VMware logo representing the critical vCenter vulnerability" loading="lazy" src="https://blog.comfidentia.cl/images/posts/cisa-warns-ransomware-gangs-exploiting-critical-vmware-vcent-0-0b0ba765b3.jpg"&gt;
&lt;em&gt;Original image source: &lt;a href="https://www.bleepstatic.com/content/hl-images/2024/11/18/VMware.jpg"&gt;bleepstatic.com&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/br&gt;&lt;/p&gt;
&lt;p&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that ransomware gangs are now actively exploiting a critical VMware vCenter vulnerability, identified as &lt;strong&gt;CVE-2026-59310&lt;/strong&gt;, which was patched in July. This development comes after an initial wave of attacks suspected to be from advanced persistent threat (APT) actors.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/br&gt;&lt;/p&gt;
&lt;h2 id="detalles-de-la-vulnerabilidad-y-su-explotación"&gt;Detalles de la Vulnerabilidad y su Explotación&lt;/h2&gt;
&lt;p&gt;Broadcom, the company behind VMware, addressed CVE-2026-59310 on July 29, classifying it as a critical directory traversal flaw within the vCenter Syslog server. This vulnerability allows unauthenticated attackers to execute arbitrary code on affected systems. At the time of the patch release, Broadcom urged customers to prioritize its remediation, emphasizing the urgency of applying updates.&lt;/p&gt;</description></item></channel></rss>