CISA: Ransomware Gangs Now Exploiting Critical VMware vCenter RCE Flaw
The Cybersecurity and Infrastructure Security Agency warns that a critical directory traversal vulnerability is being used to target virtualized infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that ransomware gangs are actively exploiting a critical remote code execution (RCE) vulnerability in VMware vCenter Server. The flaw allows attackers to gain unauthorized access to the control plane of virtualized environments, posing a severe risk to corporate data integrity.
Tracked as CVE-2026-59310, the vulnerability is a critical directory traversal flaw located within the vCenter Syslog server. Broadcom released an emergency patch for the vulnerability on July 29, urging customers to apply the fix immediately. CISA has since added the flaw to its Known Exploited Vulnerabilities (KEV) Catalog, specifically flagging its use in ongoing ransomware campaigns.
The Shift to Ransomware
Before the current wave of ransomware activity, the vulnerability was utilized by a suspected advanced persistent threat (APT) actor. According to DFIR firm QUIRSO, this actor exploited the flaw to deploy reverse SSH tools for persistence across compromised systems in 47 different countries. This initial phase of exploitation focused on stealth and long-term access rather than immediate disruption.
High-Value Infrastructure Targets
VMware vCenter and ESXi servers are primary targets for threat actors because they function as the central control plane for an organization's virtualized infrastructure. Gaining root-level access to these systems effectively provides the "keys to the kingdom," granting attackers the ability to access numerous internal virtual machines and sensitive corporate data simultaneously. This vulnerability is part of a broader trend; over the last five years, CISA has tagged 26 VMware vulnerabilities as exploited in the wild, with nine of those specifically abused by ransomware operations.
Industry Implications
The transition from APT-led espionage to ransomware exploitation signals a shift toward the immediate financial monetization of the flaw. Because vCenter manages the entire virtual environment, a single successful compromise can lead to the simultaneous encryption of an organization's entire server infrastructure. This capability maximizes the leverage of ransomware gangs during extortion demands, as it can paralyze an entire enterprise's operations in one move.
What to Watch
Organizations that have not yet updated their vCenter Server installations remain at high risk. Security teams should prioritize the July 29 patch and audit their environments for signs of reverse SSH tools, which may indicate a prior breach by APT actors. While the patch addresses the directory traversal flaw, the industry continues to monitor for further variants of this exploit as ransomware groups refine their deployment methods.