CISA warned that ransomware gangs are now abusing the critical VMware vCenter vulnerability CVE-2026-59310, which Broadcom patched in July as an urgent directory traversal flaw. Security teams were urged to patch immediately after reports showed the bug was already being used for persistence and remote access across hundreds of exposed vCenter systems. #CVE-2026-59310 #VMwarevCenter #Broadcom #CISA #QUIRSO #Shadowserver
Keypoints
- CVE-2026-59310 is a critical VMware vCenter directory traversal flaw.
- Broadcom said unauthenticated attackers could use it to execute arbitrary code.
- QUIRSO found over 361 IP addresses compromised in 47 countries.
- CISA added the flaw to its KEV Catalog and ordered rapid patching.
- Ransomware gangs are now actively exploiting exposed VMware vCenter servers.