bleeping-computer · Crawled Sep 15, 2026

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that the critical VMware vCenter vulnerability CVE-2026-59310, a directory traversal flaw allowing unauthenticated remote code execution, is now actively exploited by ransomware gangs. The vulnerability was patched by Broadcom in July 2026, but attackers have been observed exploiting unpatched systems to deploy reverse SSH tools for persistence and remote access. CISA added the flaw to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate within three days. The broader threat landscape shows a pattern of ransomware groups targeting VMware infrastructure due to its strategic access to enterprise networks and data.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.