CVE Tools

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

BleepingComputerBy Sergiu Gatlan

Reported exploitedVMware vCenter ServerRansomware gangs

Our summary

CISA says ransomware gangs are actively exploiting CVE-2026-59310 in VMware vCenter Server, a vulnerability Broadcom patched in July. The directory traversal flaw in the vCenter Syslog server can let unauthenticated attackers execute arbitrary code, putting organizations' virtual infrastructure and connected internal systems at risk.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store