What We Know
CISA has confirmed that ransomware operators are actively exploiting CVE-2026-59310, a critical vulnerability in VMware vCenter Server.3Backed by 3 sourcesinsight.tmcnet.comBleepingComputeraviatrix.ai The vulnerability is described as a directory or path-traversal flaw in vCenter’s Syslog server that can enable remote code execution, and reports characterize it as exploitable without authentication.2Backed by 2 sourcessafeguard.shcybersecuretoday.com
The flaw has been associated with ransomware attacks, raising the risk that compromised vCenter systems could provide attackers with a route into virtualized environments.3Backed by 3 sourcesBleepingComputersafeguard.shcybersecuretoday.com CISA’s warning has prompted urgent remediation guidance for federal agencies, while reporting on the broader victim population and the scale of exploitation remains limited in the supplied material.1Backed by 1 sourcescybersecuretoday.com One report additionally links exploitation to a suspected China-linked group and Babuk ransomware, but that attribution is presented as suspected rather than established.1Backed by 1 sourcesthecisobrief.com
The vulnerability is described as having a CVSS 9.8 severity rating in reporting that also references ransomware activity.1Context from one sourceshattered.io
Source Comparison
Aligned reportingCorroborates
- insight.tmcnet.com↗Supports the briefing’s central account that CISA reported active ransomware exploitation of CVE-2026-59310 in VMware vCenter Server.
- BleepingComputer↗Corroborates that CISA reported ransomware gangs exploiting a critical VMware vCenter remote-code-execution flaw and connects the vulnerability with ransomware activity.
- safeguard.sh↗Supports the technical description of CVE-2026-59310 as a vCenter Syslog path-traversal flaw and links it to ransomware.
- aviatrix.ai↗Corroborates CISA’s reported confirmation of active ransomware exploitation of the critical VMware vCenter vulnerability.
- cybersecuretoday.com↗Supports the path-traversal and unauthenticated-exploitation description, the ransomware connection, and urgent federal remediation guidance.
- thecisobrief.com↗Corroborates the reported but qualified attribution linking exploitation to a suspected China-linked group and Babuk ransomware.