ConicPlex

Start Your Project

A server rack in a data center glows amber in warning next to a broken padlock, symbolizing the VMware vCenter ransomware exploitation of CVE-2026-59310

On this Page

Ransomware Gangs Exploit Critical VMware vCenter Flaw (CVE-2026-59310)

CISA confirms ransomware gangs are exploiting CVE-2026-59310, a critical VMware vCenter flaw rated CVSS 9.8. Here’s what’s affected and how to respond.

Sameer Malek

September 16, 2026

CISA confirmed on September 15, 2026 that ransomware operators have joined an already active exploitation campaign against CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter Server’s Syslog service. The flaw carries a CVSS score of 9.8 and lets an unauthenticated attacker run arbitrary code on an exposed vCenter instance. Broadcom patched it in late July, but attackers started exploiting it within days of disclosure, and researchers have now tracked hundreds of compromised servers across dozens of countries.

Broadcom disclosed CVE-2026-59310 alongside a related authentication bypass bug, CVE-2026-59309, in advisory VMSA-2026-0006 on July 29. Both carry the same 9.8 CVSS score. Within about five days, threat actors were already dropping open source reverse shells on compromised servers to hold onto access. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 18 and gave federal agencies three days to patch or take exposed systems offline, flagging it for forensic triage under BOD 26-04 rather than a simple patch-and-move-on.

What Changed with CVE-2026-59310 This Week

The vulnerability itself isn’t new. What changed over the past few days is who’s using the access. Multiple ransomware groups are now working off the same foothold that espionage-focused attackers established over the summer, according to CISA’s updated guidance. Threat intel firm QUIRSO has linked the campaign to more than 360 compromised IP addresses across 47 countries, and Shadowserver still counts over 450 vCenter servers reachable from the open internet as of this week.

vCenter sits at the center of most VMware deployments. It’s the control plane for provisioning, snapshots, and access across every VM on a cluster, so a successful exploit doesn’t just hand an attacker one server, it hands them a path to everything vCenter manages. That’s a very different blast radius than a single compromised application server, and it’s exactly why an unpatched, internet-facing vCenter instance from July is now a live ransomware entry point in September.

What to Do About It Now

  • Patch to the fixed version listed in Broadcom’s response matrix for VMSA-2026-0006. There’s no workaround for this one, patching is the only real fix.
  • If patching can’t happen immediately, pull vCenter off the public internet and restrict access to a segmented management network.
  • Check logs for signs of earlier compromise, unfamiliar reverse shell tools, new scheduled tasks, or admin accounts you don’t recognize, since attackers have had roughly six weeks of potential access already.
  • Treat any instance that’s been internet-facing and unpatched since late July as potentially compromised, not just vulnerable.

This is the same pattern that’s played out with other high-severity path traversal and RCE bugs this year, including GitLab’s maximum-severity path traversal flaw and the actively exploited Gitea RCE flaw CISA flagged in August: a patch ships, exploitation follows within days, and the window between disclosure and real damage keeps shrinking. Infrastructure that touches production, whether it’s a Git server, a CI pipeline, or a virtualization control plane like vCenter, needs the same patch discipline as public-facing web applications. It’s worth pairing that with the kind of infrastructure hardening covered in our note on the Cloudflare Spectre attack on Workers, since both stories point to the same gap: management and edge infrastructure doesn’t get the same scrutiny as the application layer until something like this forces the issue.

Sources

Sameer Malek is a Senior Full Stack Developer at ConicPlex, working across the stack on projects that don’t fit neatly into one platform or framework. He’s often the person weighing a genuine platform or architecture decision rather than defending one side of it, since his work regularly crosses between WordPress, custom builds, and everything in between. He writes here about the comparisons and tradeoffs that come up when there’s more than one reasonable way to build something.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

Flat illustration of a size chart grid with a tape measure and clothing tag, representing WooCommerce size chart plugins

How to Add a Size Chart to a WooCommerce Product Page (4 Plugins Compared)

Four real WooCommerce plugins add a size chart to a product page: Sizor, Product Size Charts Plugin for WooCommerce, WPC…

Sajil Memon

September 17, 2026

Plugins

Illustration of a breadcrumb navigation trail shown as connected chip shapes with arrow separators, representing WordPress breadcrumb plugins

How to Add Breadcrumbs to WordPress without an SEO Plugin (4 Plugins Compared)

Four real WordPress plugins add breadcrumbs and, in most cases, schema markup without installing a full SEO plugin: Breadcrumb NavXT,…

Husen Memon

September 16, 2026

Plugins

Flat illustration of three overlapping pricing plan cards representing a comparison of WordPress pricing table block plugins

5 Pricing Table Block Plugins Built for the WordPress Block Editor

Five pricing table block plugins add a real pricing table to the WordPress block editor, not a shortcode you paste…

Sajil Memon

September 15, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant