Ransomware Operators are Exploiting a Critical VMware vCenter Flaw

What began as a vulnerability used for persistence is now attracting ransomware groups, increasing the pressure on organizations that have not yet applied Broadcom's July patch.

Security hero image

Key Takeaways:

  • CVE-2026-59310 is a critical VMware vCenter vulnerability that allows unauthenticated remote code execution.
  • CISA says ransomware operators are now exploiting the flaw after earlier activity focused on establishing persistence.
  • Organizations are being urged to prioritize patching, even if it means accelerating normal maintenance and testing schedules.

Organizations running VMware vCenter face growing risk from a critical remote code execution vulnerability (CVE-2026-59310) that ransomware operators are now actively exploiting. This flaw, which was patched by Broadcom in July, allows unauthenticated attackers to execute code on vulnerable systems, which makes exposed vCenter deployments a high-value target.

VMware vCenter is a centralized management platform that helps IT admins monitor, configure, and control virtualized environments built on VMware technology. They can use vCenter to oversee multiple hosts and virtual machines from a single console, automate routine tasks, allocate computing resources, enforce security policies, and support features such as workload balancing, backup, and disaster recovery.

How can a single vCenter compromise impact entire virtual environments?

According to CISA, initial exploitation of the CVE-2026-59310 flaw was linked to threat actors deploying persistence tools for long-term access, but ransomware groups have now joined the campaign. A successful vCenter compromise can provide attackers with access to critical systems, sensitive data, and large numbers of virtual machines.

CISA recommends that organizations should immediately apply the available security updates, review internet-facing vCenter instances, and verify that systems are not already compromised. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and requires U.S. federal agencies to remediate affected systems within days.

Emergency patching can disrupt planned maintenance schedules and require accelerated testing, but delaying remediation increases the likelihood of ransomware-related incidents. It’s advised that organizations must prioritize rapid patch deployment over their normal change-management timelines.