What We Know
TrendingJust now

Ransomware Gangs Exploit Critical VMware vCenter Vulnerability Despite Broadcom Patch

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Trending

What We Know

CISA and multiple security reports say ransomware gangs are exploiting CVE-2026-59310, a critical vulnerability affecting VMware vCenter.Backed by 3 sourcesmeterpreter.orgBleepingComputerpetri.com The flaw is described as involving vCenter’s Syslog server, with reporting characterizing it as a path-traversal vulnerability and other coverage describing it as a remote-code-execution issue.Backed by 1 sourcessafeguard.sh

Broadcom released a patch for the vulnerability in late July, with one report specifying July 29, but vulnerable systems remain exposed because organizations have not all applied it.Backed by 2 sourcesmeterpreter.orgpetri.com The reported shift from earlier exploitation for persistence to ransomware activity increases the potential impact for organizations running affected vCenter systems.Backed by 1 sourcespetri.com

Coverage characterizes CVE-2026-59310 as a remote-code-execution vulnerability with a CVSS 9.8 rating.Context from one sourceshattered.io A suspected China-linked group is reported to have used the VMware flaw to launch Babuk ransomware.Context from one sourcethecisobrief.com Broadcom is reported to have patched the vCenter Syslog bug on July 29.Context from one sourcetheclarity.today

Source Comparison

Aligned reporting
4 corroborates - 3 adds context - 0 conflicts