Executive Summary
CISA’s known-exploited catalog now records CVE-2026-59310, a path traversal in the vCenter Syslog server with a 9.8 CVSS score, as used in ransomware campaigns. Broadcom patched it on 29 July and told customers to treat remediation as an emergency. Federal agencies were given a due date of 21 August.
The pattern holds across the VMware estate. Researchers counted 361 victim addresses in 47 countries within two weeks of disclosure, and the first wave left reverse SSH tunnels that a patch does not remove. More than 450 vCenter appliances are still reachable from the internet. Ransomware crews keep choosing the hypervisor because one management plane reaches every guest and its backups.
CISA changed one field in its exploited-vulnerability catalog over the weekend. The entry for CVE-2026-59310 now reads “Known” for ransomware campaign use. That flag is the difference between a patch you schedule and an incident you are already in.
The flaw itself is a path traversal in the vCenter Syslog server. An attacker with network access needs no credentials and no user interaction. The National Vulnerability Database scores it 9.8, the top of the critical band.

Broadcom Moved Fast. Attackers Moved Faster.
Broadcom shipped fixed builds on 29 July for the vCenter 9.1, 9.0, and 8.0 branches. The VMSA-2026-0006 advisory also lists a critical authentication bypass patched in the same release. It lists no workaround, so the upgrade is the only fix.
Incident responders at QUIRSO counted 361 compromised addresses across 47 countries within two weeks of disclosure. The first operator was tracked as a suspected state-linked actor. Criminal ransomware crews have since joined them, per BleepingComputer.
Patching Closes the Hole, Not the Backdoor
This is the part operators skip. The early wave left reverse SSH tunnels on compromised appliances. That access survives the upgrade, because patching removes the vulnerability but not the account or the connection an attacker already built. Hunt for it before you close the ticket.
CISA has flagged 26 VMware vulnerabilities as exploited in the wild over five years. Nine of them were also used in ransomware attacks. That ratio is not coincidence. Management planes are worth more to an attacker than endpoints, so they attract the crews with the best tooling.
Every Guest Sits Behind One Console
vCenter is not a server you patch and forget. It is the control plane for the virtual estate. Code execution there reaches every ESXi host, datastore, and virtual switch underneath it. So crews skip the guest operating systems and encrypt VMDK and VMX files at rest instead.
Shadowserver still sees more than 450 vCenter appliances exposed to the internet. Each one is a target with a published exploit and a fix that has been available since July. The 9.8 VMware vCenter vulnerability is patched. The exposure is not, and neither is the persistence.
Related reading. Europe’s regulators are now Broadcom’s biggest VMware problem. Broadcom cut off the VMware tool that migration vendors depend on. Attackers chained three JFrog Artifactory flaws into full admin control.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.

[…] Read the full analysis at why patching vCenter does not evict the attacker. […]
[…] reading. Our coverage of the vCenter flaw CISA tied to ransomware gangs and the licensing squeeze pushing teams off VMware Cloud […]