UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

VMware vCenter RCE Ransomware Exploit 2026 — Why You Should Patch Now

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

CISA has confirmed that ransomware gangs are now exploiting a critical VMware vCenter flaw, CVE-2026-59310, patched by Broadcom in July. For operators, including those in the UK, still running on-prem or hybrid vSphere estates, this is no longer a theoretical risk — it is part of an active global campaign, and the case for tightening vulnerability management now is immediate.

Scale of the vCenter exploitation wave
4503382251130450Exposed servers361Compromised IPs47Countries hitCount
View the data behind this chart
Scale of the vCenter exploitation wave
Exposed serversCompromised IPsCountries hit
Count45036147

What CISA confirmed and when

Broadcom fixed CVE-2026-59310 on 29 July 2026, describing it as a critical directory-traversal vulnerability in the vCenter Syslog server that lets an unauthenticated attacker execute arbitrary code. Broadcom's supplemental FAQ told customers to treat the fix as an emergency and patch immediately.

Two weeks after disclosure, DFIR firm QUIRSO reported over 361 compromised IP addresses across 47 countries, tied to a suspected advanced persistent threat actor deploying a reverse SSH tool for persistent remote access. CISA then added the flaw to its Known Exploited Vulnerabilities catalog and gave U.S. federal agencies just three days to secure their vCenter systems. Over the weekend, CISA updated the KEV entry again — this time explicitly flagging active abuse by ransomware gangs in addition to earlier APT activity.

Why vCenter keeps being the ransomware entry point of choice

vCenter is the control plane for ESXi hosts and the virtual machines they run, which is exactly why it keeps appearing in ransomware playbooks. Several ransomware families now ship dedicated encryptors built specifically for VMware virtual machine formats, because compromising the management layer gives attackers a single foothold that can cascade across an entire virtual estate rather than one server at a time.

This is not an isolated incident. CISA has tagged 26 VMware vulnerabilities as exploited in the wild over the last five years, and nine of those were subsequently abused by ransomware operations. Earlier in 2026 alone, CISA flagged a VMware ESXi sandbox escape (CVE-2025-22225, exploited by ransomware groups after being used in zero-day attacks by Chinese-speaking actors since 2024), a VMware Aria Operations flaw (CVE-2026-22719), and a further vCenter Server bug (CVE-2024-37079). The pattern is consistent: disclosure, rapid weaponisation, then ransomware follow-through.

The exposure gap UK buyers can't ignore

Shadowserver currently tracks more than 450 VMware vCenter servers exposed directly to the internet, and there is no visibility into how many of those have actually been patched. That gap is the operational problem for UK data centre operators: a server can look 'managed' internally while still sitting unpatched and internet-facing, invisible to the teams responsible for it until an incident forces the question.

For hybrid and on-prem shops, vCenter compromise doesn't stay contained to virtualisation — it threatens backup infrastructure, identity systems, and any workload the platform touches. That's why organisations still running legacy or end-of-support VMware estates should treat this as a forcing function to implement robust ransomware protection strategies rather than relying on patch cadence alone.

  • Confirm every vCenter instance is patched against CVE-2026-59310, not just flagship production clusters
  • Check whether any vCenter appliance is reachable from the public internet and restrict access immediately if so
  • Review logging and alerting on the Syslog server component specifically, given that's the exploited path
Illustration: VMware vCenter RCE Ransomware Exploit 2026 — Why You Should Patch Now

Patch first, but don't stop there

Patching CVE-2026-59310 is the non-negotiable first step, but the ransomware angle changes the calculus for what comes next. Organisations should assume that any vCenter instance exposed before the July patch may already have been probed, and act accordingly — reviewing authentication logs, rotating credentials tied to the management plane, and validating that backup copies are genuinely isolated from the production environment attackers would target.

This is also the moment to understand the critical role of immutable backups in a vCenter-centric ransomware scenario. If the management plane is compromised, standard backup jobs orchestrated through the same infrastructure can be tampered with or deleted before encryption even begins. Teams should also strengthen their backup and disaster recovery plans with recovery paths that don't depend on the compromised platform being trustworthy.

A wider question: renew, harden, or move off VMware

The recurrence of critical vCenter and ESXi flaws — nine ransomware-linked exploits in five years by CISA's own count — is pushing some UK infrastructure buyers to reconsider their long-term VMware dependency, particularly as licensing and support terms shift under Broadcom ownership. That doesn't mean panic migration, but it does mean the decision deserves a proper look rather than default renewal.

Buyers weighing this should weigh their options for VMware renewal versus migration against the realistic cost of continued exposure, and where migration looks attractive, evaluate the best VMware alternatives available to UK organisations. Whichever path is chosen, the immediate priority remains the same: patch CVE-2026-59310 now, and use this incident to enhance your vulnerability management program so the next KEV update doesn't catch the estate off guard.

Share
Key takeaways
  • CVE-2026-59310 is a critical, unauthenticated directory-traversal RCE in vCenter's Syslog server, patched by Broadcom on 29 July 2026 — CISA now confirms active ransomware exploitation on top of earlier APT activity.
  • Over 450 vCenter servers remain exposed online per Shadowserver, with no visibility into how many are patched — audit internet-facing vCenter instances today.
  • This is the ninth ransomware-linked VMware CVE CISA has flagged in five years out of 26 exploited-in-the-wild bugs, showing vCenter/ESXi remains a persistent, recurring target.
  • Patch immediately, then harden backup isolation and review whether continued VMware reliance still makes sense against ongoing exploitation trends.
Frequently asked

FAQs — VMware vCenter RCE Ransomware Exploit 2026

What is CVE-2026-59310?

It's a critical directory-traversal vulnerability in the VMware vCenter Syslog server that allows unauthenticated attackers to execute arbitrary code remotely. Broadcom patched it on 29 July 2026 and urged emergency remediation.

Has ransomware exploitation of this flaw been confirmed?

Yes. CISA updated its Known Exploited Vulnerabilities catalog over the weekend to flag CVE-2026-59310 as actively abused by ransomware gangs, following earlier reports of a suspected APT actor using it for reverse SSH persistence across 361 IPs in 47 countries.

How many vCenter servers are still exposed?

Shadowserver currently tracks more than 450 VMware vCenter servers exposed directly to the internet. There's no public data on how many of those have been patched, which is why organisations should audit their own exposure rather than assume they're covered.

What should UK infrastructure teams do right now?

Patch every vCenter instance against CVE-2026-59310 immediately, restrict any internet-facing access to the management plane, review authentication logs for signs of prior compromise, and confirm backups are isolated using approaches like immutable backups.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111