Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-16 Β· updated: 2026-09-16 Β· tags: [incident, government, ransomware] Β· confidence: high Β· severity: critical Β· affected_sectors: [government] Β· au_impact: true

CISA has updated its Known Exploited Vulnerabilities catalogue to record that ransomware gangs are now among those exploiting CVE-2026-59310, the critical directory-traversal vulnerability in the VMware vCenter Syslog server that Broadcom patched on 29 July. The flaw allows unauthenticated attackers to execute arbitrary code, and Broadcom's own supplemental FAQ at the time told customers to treat remediation as an emergency and patch as soon as possible. The exploitation history since then is the part worth tracking: two weeks after the patch, the incident-response firm QUIRSO reported finding more than 361 IP addresses across 47 countries compromised after a suspected advanced persistent threat actor began exploiting the flaw to deploy a reverse SSH tool for persistence and remote access. CISA added the CVE to the KEV catalogue on 18 August and ordered US federal agencies to secure their vCenter systems within three days. The update now attributed to ransomware operations is a second escalation of the same identifier rather than a new vulnerability, and CISA has not published details of which ransomware groups are involved or which victims have been hit. The exposure baseline is the concrete risk figure: internet monitor Shadowserver currently tracks more than 450 VMware vCenter servers reachable from the internet, with no public information on how many have been patched. Iran's and other actors' use of reverse SSH for persistence follows a pattern this digest has tracked through Fire Ant's pivot from VMware hypervisors to Cisco routers; the reason vCenter recurs as a target is structural β€” a compromised vCenter or ESXi host provides reconnaissance across the virtual estate and a route to the data stored on it, which is why multiple ransomware families now maintain dedicated ESXi encryptors. Any organisation still running an unpatched vCenter Syslog endpoint should treat the flaw as exploited, not merely exposed.

Attribute Detail
Sector Government
Date 2026-09-16
Source BleepingComputer
Reliability Tier 2
CVEs CVE-2026-59310