CISA: Critical VMware RCE flaw now exploited by ransomware gangs
Reported exploitedVMware vCenter ServerRansomware gangsOur summary
CISA says ransomware gangs are actively exploiting CVE-2026-59310 in VMware vCenter Server, a vulnerability Broadcom patched in July. The directory traversal flaw in the vCenter Syslog server can let unauthenticated attackers execute arbitrary code, putting organizations' virtual infrastructure and connected internal systems at risk.
Read at BleepingComputer
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.