What We Know
CISA and multiple security reports say ransomware gangs are exploiting CVE-2026-59310, a critical vulnerability affecting VMware vCenter.3Backed by 3 sourcesmeterpreter.orgBleepingComputerpetri.com The flaw is described as involving vCenter’s Syslog server, with reporting characterizing it as a path-traversal vulnerability and other coverage describing it as a remote-code-execution issue.1Backed by 1 sourcessafeguard.sh
Broadcom released a patch for the vulnerability in late July, with one report specifying July 29, but vulnerable systems remain exposed because organizations have not all applied it.2Backed by 2 sourcesmeterpreter.orgpetri.com The reported shift from earlier exploitation for persistence to ransomware activity increases the potential impact for organizations running affected vCenter systems.1Backed by 1 sourcespetri.com
Coverage characterizes CVE-2026-59310 as a remote-code-execution vulnerability with a CVSS 9.8 rating.1Context from one sourceshattered.io A suspected China-linked group is reported to have used the VMware flaw to launch Babuk ransomware.1Context from one sourcethecisobrief.com Broadcom is reported to have patched the vCenter Syslog bug on July 29.1Context from one sourcetheclarity.today
Source Comparison
Aligned reportingCorroborates
- meterpreter.org↗Supports the account that ransomware gangs are exploiting the critical VMware vCenter flaw and that a patch has existed since late July.
- BleepingComputer↗Reports CISA's warning that ransomware gangs have joined ongoing attacks exploiting a critical VMware vCenter RCE flaw.
- petri.com↗Supports the shift from persistence-related exploitation to ransomware activity and links continued exposure to organizations that have not applied Broadcom's July patch.
- safeguard.sh↗Identifies the issue as a path-traversal bug in vCenter's Syslog server and connects it to ransomware activity.
Adds context
- shattered.io↗Characterizes CVE-2026-59310 as a remote-code-execution vulnerability and gives it a CVSS 9.8 rating, adding technical severity context.
- thecisobrief.com↗Adds a reported attribution and payload detail by describing a suspected China-linked group using the VMware flaw to launch Babuk ransomware.
- theclarity.today↗Specifies July 29 as the date Broadcom patched the vCenter Syslog bug and notes ransomware gangs moving onto it.