CISA Warns of Critical VMware RCE Vulnerability Exploited by Ransomware Gangs
U.S. Cybersecurity and Infrastructure Security Agency warns of active ransomware exploitation of a critical VMware vulnerability.
CISA’s Warning on VMware Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency issued a warning to security teams that ransomware groups have begun leveraging a critical vulnerability in VMware vCenter systems.
Vulnerability Details and Patch
The flaw, designated CVE-2026-59310, was addressed by Broadcom on July 29 as a directory traversal issue within the vCenter Syslog server. This flaw allows unauthenticated attackers to execute arbitrary code, posing a severe risk to affected environments. The company emphasized the urgency of applying patches, labeling the fix as an emergency in a supplementary FAQ.
Incident Response Findings
Two weeks after the patch release, a digital forensics and incident response firm, QUIRSO, identified over 361 compromised IP addresses across 47 countries. The breach was linked to an advanced persistent threat actor deploying a reverse SSH tool to maintain persistence and establish remote access.
CISA’s KEV Inclusion
Subsequently, CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog, mandating government agencies to secure their vCenter systems within three days. The agency later updated the KEV list to explicitly note the vulnerability’s active exploitation by ransomware groups.
Exposure Statistics
Shadowserver, an internet security threat monitor, reports more than 450 VMware vCenter servers exposed online. However, no data is available on the number of these systems that have been patched against this specific flaw.
Why VMware is Targeted
VMware systems remain a prime target for ransomware actors due to their role in managing enterprise networks and storing sensitive data. Compromised vCenter or ESXi servers provide attackers with pathways to internal infrastructure, making them high-value targets.
Previous Vulnerabilities
Recent years have seen multiple ransomware groups develop specialized encryption tools to target VMware virtual machines. This trend aligns with the increasing adoption of VMware solutions by enterprises for data management. CISA previously highlighted the exploitation of a VMware ESXi sandbox escape vulnerability (CVE-2025-22225) by Chinese-speaking threat actors in zero-day attacks since February 2024.
CISA’s History with VMware Flaws
The agency has also flagged other VMware flaws, including CVE-2026-22719 and CVE-2024-37079, as actively exploited in attacks during 2026. Over the past five years, CISA has identified 26 VMware vulnerabilities as exploited in the wild, with nine of these also linked to ransomware operations.
Conclusion and Recommendations
The ongoing exploitation of these flaws underscores the critical need for timely patching and proactive security measures. Organizations are advised to review their VMware environments for compliance with mitigation guidelines and to monitor for signs of compromise.
