CISA: Critical VMware RCE flaw now exploited by ransomware gangs
CISA warns ransomware gangs now exploit critical VMware vCenter syslog RCE CVE-2026-59310, already KEV-listed after APT compromises across 47 countries.
Broadcom patched critical directory traversal flaw CVE-2026-59310 in the vCenter Syslog server on July 29, warning of unauthenticated remote code execution. QUIRSO subsequently found 361 compromised IPs across 47 countries after a suspected APT deployed a reverse SSH tool for persistence and remote access. CISA added the flaw to its KEV catalog with a three-day patch deadline for federal agencies, and over the weekend updated it to flag active abuse by ransomware gangs. Shadowserver tracks over 450 exposed vCenter servers, and CISA has tagged 26 VMware vulnerabilities as exploited in the wild over five years, nine abused by ransomware.
- CVE-2026-59310: critical unauth directory traversal RCE in vCenter Syslog server, patched July 29
- Suspected APT compromised 361 IPs in 47 countries using reverse SSH persistence
- KEV catalog updated to flag active ransomware gang exploitation
- Over 450 vCenter servers currently exposed online per Shadowserver
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-37079 | Out-of-bounds Write in Broadcom VMware vCenter Server DCERPC Enables RCE CVE-2024-37079 is an out-of-bounds write (CWE-787) in the implementation of the DCERPC protocol in VMware vCenter Server, Broadcom's management platform for vSphere virtualization environments. A malicious actor with network access to a vulnerable vCenter Server can trigger the flaw by sending specially crafted network packets, corrupting memory and potentially achieving remote code execution on the server. Successful exploitation would give an attacker control of a central management component, typically a strong foothold for lateral movement across the virtualized estate, though ransomware use is currently listed as unknown. Any organization running affected vCenter Server builds is exposed, with risk highest where the management interface is reachable from untrusted networks or the internet. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-01-23, confirming exploitation in the wild; no public PoC is known, CVSS was not yet scored in the source data, and the high EPSS score (22.4%, 98th percentile) signals elevated near-term exploitation risk. Do: Upgrade vCenter Server to a patched release per Broadcom's 2024 advisory (VMSA-2024-0012) without delay, since exploitation is confirmed in the wild and CISA BOD 22-01 requires federal agencies to apply vendor mitigations or discontinue use per the KEV deadline. Inventory your vCenter builds and compare them against the advisory's affected ranges; installations already patched for the 2024 DCERPC fixes are protected. Until patching completes, restrict network access to vCenter management interfaces (firewall allowlisting or VPN) and prioritize any internet-exposed instances. | 9.8 | 22% | KEV |
| large≈tens of thousands of internet-exposed vCenter instances, with total deployments plausibly in the hundreds of thousands | |
| CVE-2025-22225 | Sandbox Escape via Arbitrary Kernel Write in VMware ESXi (Actively Exploited) VMware ESXi contains an arbitrary write vulnerability (CWE-787/CWE-123) in which an actor with privileges inside the VMX process can trigger a write into the kernel, escaping the ESXi sandbox. The flaw is exploited locally (AV:L), requires high privileges within the VMX process (PR:H), and involves no user interaction, so it is typically reached by chaining another ESXi/VMX bug or after an attacker already has a foothold on the host. Successful exploitation yields a sandbox escape with high confidentiality, integrity, and availability impact, effectively giving the attacker broad control at the hypervisor level. Any organization running VMware ESXi — including the ESXi components within VMware Cloud Foundation and VMware Telco Cloud Infrastructure/Platform — is potentially affected. The flaw is being exploited in the wild and was added to CISA's KEV on 2025-03-04 with known ransomware use; media reports attribute exploitation to China-linked actors, and Broadcom has released urgent patches. Do: Apply the ESXi updates released by Broadcom/VMware for CVE-2025-22225 (covering ESXi components inside VMware Cloud Foundation and Telco Cloud deployments), prioritizing internet-facing hosts, and follow CISA KEV required actions — federal agencies must remediate per BOD 22-01 deadlines. Since exploitation is confirmed in the wild with known ransomware use, check ESXi hosts for signs of compromise and restrict/remove management interfaces from the internet until patched. No public PoC is known, so rely on vendor guidance for mitigations if immediate patching is not possible. | 8.2 | <1% | KEV ransomware |
| mass≈100,000–1,000,000 ESXi hosts deployed worldwide, with tens of thousands of ESXi instances directly exposed to the internet | |
| CVE-2025-60710 | Link Following Privilege Escalation in Microsoft Windows Host Process for Tasks CVE-2025-60710 is a link-following flaw (CWE-59, improper link resolution before file access) in the Host Process for Windows Tasks on Microsoft Windows. A local attacker with limited (low-privilege) access can trigger the flaw by causing the host process to follow a manipulated link or junction/symlink during file access, redirecting its privileged file operations. Successful exploitation yields elevation of privilege on the local system, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8). Affected systems are Windows 11 24H2, Windows 11 25H2, and Windows Server 2025. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-13 with known ransomware use, and EPSS estimates a 4.6% chance of exploitation in the next 30 days (91st percentile). Do: Apply Microsoft's current security updates for Windows 11 24H2, Windows 11 25H2, and Windows Server 2025 as soon as possible, prioritizing servers and workstations accessible to ransomware operators; the local attack vector means any compromised low-privileged account or endpoint is sufficient. Federal agencies and BOD 22-01-covered organizations must remediate or apply vendor mitigations per the KEV required action within the standard KEV timeline. Inventory systems still running unpatched 24H2/25H2 and Server 2025 builds, and monitor for post-compromise local privilege escalation activity as part of ransomware incident response. | 7.8 | 5% | KEV ransomware |
| masshundreds of millions of endpoints (Windows 11 24H2/25H2 workstations plus Windows Server 2025 deployments) | |
| CVE-2026-22719 | Unauthenticated Command Injection RCE in Broadcom VMware Aria Operations Broadcom's VMware Aria Operations (formerly vRealize Operations) contains a command injection flaw (CWE-77, CVSS 3.1 base score 8.1) that allows a malicious unauthenticated remote actor to execute arbitrary operating-system commands. The vulnerability is only exploitable while a support-assisted product migration is in progress, which narrows the attack window but requires no privileges or user interaction. Successful exploitation yields remote code execution on the affected Aria Operations instance. Organizations running Aria Operations standalone or as part of VMware Cloud Foundation, VMware Telco Cloud Infrastructure, or VMware Telco Cloud Platform are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-03, and its EPSS score of 17.4% (97th percentile) indicates elevated near-term exploitation risk. Do: Apply the patches listed in the Fixed Version column of the Response Matrix in VMSA-2026-0001 (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947). If patching must be delayed, implement the workarounds documented in the Workarounds column of the same Response Matrix and defer any support-assisted product migrations until systems are patched. Federal agencies must follow BOD 22-01 guidance given the KEV listing; all defenders should check whether support-assisted migrations are in progress or scheduled on their Aria Operations instances. | 8.1 | 17% | KEV |
| large≈10,000–100,000 enterprise deployments of Aria Operations worldwide, with only instances running a support-assisted migration exploitable at any given time | |
| CVE-2026-59310 | Unauthenticated Path Traversal RCE in Broadcom VMware vCenter Server Syslog CVE-2026-59310 is a directory traversal (CWE-22) vulnerability in the Syslog server component of VMware vCenter Server, rated critical at CVSS 9.8. It can be triggered over the network without authentication or user interaction, allowing a malicious actor with network access to vCenter to achieve arbitrary code execution. An attacker who exploits it gains code execution on the vCenter appliance, and reported campaigns show it has been used to establish persistent remote access and, by a suspected China-nexus actor, to deploy Babuk ransomware. Any organization running an affected version of vCenter Server is exposed, especially where the management interface is reachable from the internet; the available data does not specify affected version ranges. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-08-18, it was reportedly exploited just five days after disclosure, and EPSS estimates a 45.9% probability of exploitation within 30 days (99th percentile). Do: Upgrade vCenter Server to the patched release identified in Broadcom's advisory (no specific version ranges are provided in this data) and prioritize any vCenter that is internet-facing, in line with CISA KEV and BOD 26-04 requirements for federal agencies. Until patched, restrict access to the vCenter management interface to trusted networks and verify whether the vCenter Syslog server is enabled. Hunt for compromise indicators, including unexplained remote-access persistence and Babuk ransomware artifacts, given the documented China-nexus exploitation. | 9.8 | 46% | KEV ransomware |
| largeApproximately 50,000-100,000 internet-exposed vCenter Server instances, with total deployments (including internal-only) likely in the hundreds of thousands |
Full article422 words · extracted from bleepingcomputer.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.
The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.
Two weeks later, digital forensics and incident response (DFIR) company QUIRSO reported finding over 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat (APT) actor began exploiting the vulnerability to deploy a reverse SSH tool for persistence and remote access.
Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days.
Over the weekend, CISA updated its KEV catalog again to flag the security vulnerability as actively abused by ransomware gangs.
Internet security threat monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online; however, there is no information on how many have already been patched against this flaw.
VMware targeted by ransomware gangs
While the U.S. cybersecurity agency has yet to share any details about the ransomware attacks targeting CVE-2025-60710, VMware servers are commonly targeted because compromised vCenter or ESXi servers can provide access to an organization's network and sensitive data stored on internal systems.
In recent years, multiple ransomware gangs have developed dedicated encryptors to target VMware virtual machines, as enterprise organizations now commonly use them to manage and store corporate data.
CISA also warned in February that ransomware groups began exploiting a VMware ESXi sandbox escape vulnerability (CVE-2025-22225), which Chinese-speaking threat actors have targeted in zero-day attacks since at least February 2024.
Since the start of the year, the cybersecurity agency has also flagged VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) flaws as exploited in attacks in February and March.
Over the last five years, CISA has tagged 26 VMware vulnerabilities as exploited in the wild, nine of them also abused by ransomware operations.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/