Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Philippines’ Bangsamoro Autonomous Region Endures Bumpy Peace Election

    September 16, 2026

    Manchester derby VAR error caused by ‘tunnel vision’: Pro Ref chief Webb | Football

    September 16, 2026

    Carney’s new love-in with EU has everything to do with Trump

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Philippines’ Bangsamoro Autonomous Region Endures Bumpy Peace Election
    • Manchester derby VAR error caused by ‘tunnel vision’: Pro Ref chief Webb | Football
    • Carney’s new love-in with EU has everything to do with Trump
    • Mayors could be given powers to oversee water companies under government plan
    • AI app ads promoting ‘objectification of women’ banned by watchdog
    • CISA: Critical VMware RCE flaw now exploited by ransomware gangs
    • US Charges Robinhood Engineers Over Crypto Listing Trades
    • Scientists discover a major brain shift between ages 50 and 75
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA: Critical VMware RCE flaw now exploited by ransomware gangs

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.

    Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.

    The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.

    Two weeks later, digital forensics and incident response (DFIR) company QUIRSO reported finding over 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat (APT) actor began exploiting the vulnerability to deploy a reverse SSH tool for persistence and remote access.

    Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days.

    Over the weekend, CISA updated its KEV catalog again to flag the security vulnerability as actively abused by ransomware gangs.

    Internet security threat monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online; however, there is no information on how many have already been patched against this flaw.

    VMware targeted by ransomware gangs

    While the U.S. cybersecurity agency has yet to share any details about the ransomware attacks targeting CVE-2025-60710, VMware servers are commonly targeted because compromised vCenter or ESXi servers can provide access to an organization’s network and sensitive data stored on internal systems.

    In recent years, multiple ransomware gangs have developed dedicated encryptors to target VMware virtual machines, as enterprise organizations now commonly use them to manage and store corporate data.

    CISA also warned in February that ransomware groups began exploiting a VMware ESXi sandbox escape vulnerability (CVE-2025-22225), which Chinese-speaking threat actors have targeted in zero-day attacks since at least February 2024.

    Since the start of the year, the cybersecurity agency has also flagged VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) flaws as exploited in attacks in February and March.

    Over the last five years, CISA has tagged 26 VMware vulnerabilities as exploited in the wild, nine of them also abused by ransomware operations.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    CISA critical Exploited Flaw gangs ransomware RCE VMware
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

    LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

    Acronis warns of actively exploited flaw in its cPanel backup plugin

    Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Exein Secures $270M at $1.7B Valuation for Physical AI Security

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Philippines’ Bangsamoro Autonomous Region Endures Bumpy Peace Election

    September 16, 2026

    Manchester derby VAR error caused by ‘tunnel vision’: Pro Ref chief Webb | Football

    September 16, 2026

    Carney’s new love-in with EU has everything to do with Trump

    September 16, 2026

    Mayors could be given powers to oversee water companies under government plan

    September 16, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Philippines’ Bangsamoro Autonomous Region Endures Bumpy Peace Election

    September 16, 2026

    Manchester derby VAR error caused by ‘tunnel vision’: Pro Ref chief Webb | Football

    September 16, 2026

    Carney’s new love-in with EU has everything to do with Trump

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.