CISA has confirmed that ransomware gangs are now exploiting a critical VMware vCenter flaw, CVE-2026-59310, patched by Broadcom in July. For operators, including those in the UK, still running on-prem or hybrid vSphere estates, this is no longer a theoretical risk — it is part of an active global campaign, and the case for tightening vulnerability management now is immediate.
View the data behind this chart
| Exposed servers | Compromised IPs | Countries hit | |
|---|---|---|---|
| Count | 450 | 361 | 47 |
What CISA confirmed and when
Broadcom fixed CVE-2026-59310 on 29 July 2026, describing it as a critical directory-traversal vulnerability in the vCenter Syslog server that lets an unauthenticated attacker execute arbitrary code. Broadcom's supplemental FAQ told customers to treat the fix as an emergency and patch immediately.
Two weeks after disclosure, DFIR firm QUIRSO reported over 361 compromised IP addresses across 47 countries, tied to a suspected advanced persistent threat actor deploying a reverse SSH tool for persistent remote access. CISA then added the flaw to its Known Exploited Vulnerabilities catalog and gave U.S. federal agencies just three days to secure their vCenter systems. Over the weekend, CISA updated the KEV entry again — this time explicitly flagging active abuse by ransomware gangs in addition to earlier APT activity.
Why vCenter keeps being the ransomware entry point of choice
vCenter is the control plane for ESXi hosts and the virtual machines they run, which is exactly why it keeps appearing in ransomware playbooks. Several ransomware families now ship dedicated encryptors built specifically for VMware virtual machine formats, because compromising the management layer gives attackers a single foothold that can cascade across an entire virtual estate rather than one server at a time.
This is not an isolated incident. CISA has tagged 26 VMware vulnerabilities as exploited in the wild over the last five years, and nine of those were subsequently abused by ransomware operations. Earlier in 2026 alone, CISA flagged a VMware ESXi sandbox escape (CVE-2025-22225, exploited by ransomware groups after being used in zero-day attacks by Chinese-speaking actors since 2024), a VMware Aria Operations flaw (CVE-2026-22719), and a further vCenter Server bug (CVE-2024-37079). The pattern is consistent: disclosure, rapid weaponisation, then ransomware follow-through.
The exposure gap UK buyers can't ignore
Shadowserver currently tracks more than 450 VMware vCenter servers exposed directly to the internet, and there is no visibility into how many of those have actually been patched. That gap is the operational problem for UK data centre operators: a server can look 'managed' internally while still sitting unpatched and internet-facing, invisible to the teams responsible for it until an incident forces the question.
For hybrid and on-prem shops, vCenter compromise doesn't stay contained to virtualisation — it threatens backup infrastructure, identity systems, and any workload the platform touches. That's why organisations still running legacy or end-of-support VMware estates should treat this as a forcing function to implement robust ransomware protection strategies rather than relying on patch cadence alone.
- •Confirm every vCenter instance is patched against CVE-2026-59310, not just flagship production clusters
- •Check whether any vCenter appliance is reachable from the public internet and restrict access immediately if so
- •Review logging and alerting on the Syslog server component specifically, given that's the exploited path

Patch first, but don't stop there
Patching CVE-2026-59310 is the non-negotiable first step, but the ransomware angle changes the calculus for what comes next. Organisations should assume that any vCenter instance exposed before the July patch may already have been probed, and act accordingly — reviewing authentication logs, rotating credentials tied to the management plane, and validating that backup copies are genuinely isolated from the production environment attackers would target.
This is also the moment to understand the critical role of immutable backups in a vCenter-centric ransomware scenario. If the management plane is compromised, standard backup jobs orchestrated through the same infrastructure can be tampered with or deleted before encryption even begins. Teams should also strengthen their backup and disaster recovery plans with recovery paths that don't depend on the compromised platform being trustworthy.
A wider question: renew, harden, or move off VMware
The recurrence of critical vCenter and ESXi flaws — nine ransomware-linked exploits in five years by CISA's own count — is pushing some UK infrastructure buyers to reconsider their long-term VMware dependency, particularly as licensing and support terms shift under Broadcom ownership. That doesn't mean panic migration, but it does mean the decision deserves a proper look rather than default renewal.
Buyers weighing this should weigh their options for VMware renewal versus migration against the realistic cost of continued exposure, and where migration looks attractive, evaluate the best VMware alternatives available to UK organisations. Whichever path is chosen, the immediate priority remains the same: patch CVE-2026-59310 now, and use this incident to enhance your vulnerability management program so the next KEV update doesn't catch the estate off guard.
- 01BleepingComputer — CISA: Critical VMware RCE flaw now exploited by ransomware gangs · 15 September 2026
- 02The Hacker News — Suspected China-nexus actor exploits VMware vCenter flaw · 1 August 2026
- 03BleepingComputer — VMware confirms critical vCenter flaw now exploited in attacks · 1 August 2026
- 04BleepingComputer — Broadcom fixes three VMware zero-days exploited in attacks · 1 January 2026
- 05bleepingcomputer.com
- 06bleepingcomputer.com
- 07bleepingcomputer.com
- 08bleepingcomputer.com
