IGMPI facebook CISA Warns of Ransomware Exploitation of Critical VMware vCenter Vulnerability
IGMPI Logo
Centre for Cyber Forensic and Cyber Security

(An Autonomous Body Recognized by Ministry of Commerce & Industry, Government of India)

Competency based placement focussed Education | Training | Research | Consultancy

18001031071 (Toll Free), +91 11 26512850
Regular | Part-time (Online Live Classes) Modes
CISA Warns of Ransomware Exploitation of Critical VMware vCenter Vulnerability

CISA Warns of Ransomware Exploitation of Critical VMware vCenter Vulnerability

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned organisations that ransomware groups are exploiting a critical vulnerability in VMware vCenter Server. The flaw, identified as CVE-2026-59310, affects the vCenter Syslog server and can allow an unauthenticated attacker with network access to execute arbitrary code.

Broadcom, VMware's parent company, released security updates for the vulnerability on July 29 and advised customers to treat the issue as an emergency. Despite the availability of patches, attackers continued targeting vulnerable systems.

CISA initially added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalogue after evidence of active exploitation emerged. The agency has now updated the listing to indicate that ransomware operators are also using the flaw.

Digital forensics and incident response firm QUIRSO reported that more than 361 IP addresses across 47 countries had been compromised after attackers began exploiting the vulnerability. Investigators observed the use of a reverse SSH tool, which can provide attackers with persistent remote access to compromised environments.

VMware infrastructure has increasingly become a target for ransomware operators because vCenter can provide centralised control over virtual machines and ESXi hosts. Gaining access to this management layer can therefore provide attackers with opportunities to move deeper into an organisation's virtual environment.

CISA's warning highlights the continued risk posed by vulnerabilities that remain unpatched after security updates have been released. Organisations using affected VMware vCenter versions are being urged to apply the appropriate fixes and investigate their environments for possible signs of compromise.

Security teams are also advised to examine administrator accounts, remote connections and other unusual activity that could indicate attackers gained access before the systems were patched.

15-09-2026