CISA’s exploited-vulnerability catalog now lists a VMware vCenter vulnerability patched in July as used in ransomware campaigns, and that flag matters more than the patch itself.
- CVE-2026-59310 is a path traversal in the vCenter Syslog server. CVSS 9.8, no credentials, no user interaction.
- Broadcom shipped fixed builds on 29 July, in vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and 8.0 U2f. The advisory lists no workaround.
- CISA added it to the catalog on 18 August with a due date of 21 August, then updated the entry over the weekend to flag known ransomware campaign use.
- QUIRSO counted 361 victim addresses across 47 countries within two weeks of disclosure. The first wave left reverse SSH tunnels that survive an upgrade.
- Shadowserver still sees more than 450 vCenter appliances reachable from the internet.
- CISA has flagged 26 VMware vulnerabilities as exploited in five years. Nine of them were also used by ransomware crews.
Read the full analysis at why patching vCenter does not evict the attacker.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
