# CISA flags ransomware use of VMware vCenter flaw

_Tuesday, September 15, 2026 at 8:16 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![CISA flags ransomware use of VMware vCenter flaw — Primary](https://www.bleepstatic.com/content/hl-images/2024/11/18/VMware.jpg)

CISA updated its Known Exploited Vulnerabilities catalog to say ransomware gangs are actively abusing CVE-2026-59310, a critical VMware vCenter directory-traversal flaw patched by Broadcom in July, BleepingComputer reported. Broadcom said unauthenticated attackers could use the vCenter Syslog server flaw to execute arbitrary code. Earlier reporting identified more than 361 compromised IP addresses across 47 countries, and Shadowserver tracks more than 450 internet-exposed vCenter servers. The report does not say how many exposed systems have been patched.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/)

---
Canonical: https://techandbusiness.org/newswire/Z2rImsITSTxh0J3pqE_IbP
Retrieved: 2026-09-15T15:07:21.268Z
Publisher: Tech & Business (techandbusiness.org)
