What We Know
TrendingJust now

CISA Reports Active Ransomware Exploitation of Critical VMware vCenter Vulnerability

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Trending

What We Know

CISA has confirmed that ransomware operators are actively exploiting CVE-2026-59310, a critical vulnerability in VMware vCenter Server.Backed by 3 sourcesinsight.tmcnet.comBleepingComputeraviatrix.ai The vulnerability is described as a directory or path-traversal flaw in vCenter’s Syslog server that can enable remote code execution, and reports characterize it as exploitable without authentication.Backed by 2 sourcessafeguard.shcybersecuretoday.com

The flaw has been associated with ransomware attacks, raising the risk that compromised vCenter systems could provide attackers with a route into virtualized environments.Backed by 3 sourcesBleepingComputersafeguard.shcybersecuretoday.com CISA’s warning has prompted urgent remediation guidance for federal agencies, while reporting on the broader victim population and the scale of exploitation remains limited in the supplied material.Backed by 1 sourcescybersecuretoday.com One report additionally links exploitation to a suspected China-linked group and Babuk ransomware, but that attribution is presented as suspected rather than established.Backed by 1 sourcesthecisobrief.com

The vulnerability is described as having a CVSS 9.8 severity rating in reporting that also references ransomware activity.Context from one sourceshattered.io

Source Comparison

Aligned reporting
6 corroborates - 1 adds context - 0 conflicts