CISA: Ransomware Now Exploits Critical VMware vCenter Bug

CISA: Ransomware Now Exploits Critical VMware vCenter Bug

The Cybersecurity and Infrastructure Security Agency confirmed on September 15, 2026, that ransomware gangs have joined an already active espionage campaign targeting a critical VMware vCenter Server flaw, according to BleepingComputer. The vulnerability, tracked as CVE-2026-59310, carries a CVSS score of 9.8 and lets an unauthenticated attacker with network access to a vCenter instance execute arbitrary code through the Syslog server component. Broadcom patched the bug on July 29, 2026, but the fix arrived weeks before most administrators applied it, and that gap is now being paid for in encrypted virtual machines.