Key Takeaways:
- CVE-2026-59310 is a critical VMware vCenter vulnerability that allows unauthenticated remote code execution.
- CISA says ransomware operators are now exploiting the flaw after earlier activity focused on establishing persistence.
- Organizations are being urged to prioritize patching, even if it means accelerating normal maintenance and testing schedules.
Organizations running VMware vCenter face growing risk from a critical remote code execution vulnerability (CVE-2026-59310) that ransomware operators are now actively exploiting. This flaw, which was patched by Broadcom in July, allows unauthenticated attackers to execute code on vulnerable systems, which makes exposed vCenter deployments a high-value target.
VMware vCenter is a centralized management platform that helps IT admins monitor, configure, and control virtualized environments built on VMware technology. They can use vCenter to…

