CISA: Critical VMware RCE flaw now exploited by ransomware gangs
CISA warned that a critical VMware vCenter vulnerability (CVE-2026-59310), patched by Broadcom on July 29, is now being exploited by ransomware groups. Attackers previously used it to install reverse SSH, affecting over 361 IPs in 47 countries.
- CVE-2026-59310 is a critical directory traversal in vCenter Syslog
- Broadcom released a patch on July 29 and urged emergency installation
- QUIRSO found 361+ compromised IPs in 47 countries
- Shadowserver tracks over 450 exposed vCenter servers
Read next
Security