What began as a vulnerability used for persistence is now attracting ransomware groups, increasing the pressure on organizations that have not yet applied Broadcom's July patch.
CVE-2026-59310 is a critical VMware vCenter vulnerability that allows unauthenticated remote code execution.
CISA says ransomware operators are now exploiting the flaw after earlier activity focused on establishing persistence.
Organizations are being urged to prioritize patching, even if it means accelerating normal maintenance and testing schedules.
Organizations running VMware vCenter face growing risk from a critical remote code execution vulnerability (CVE-2026-59310) that ransomware operators are now actively exploiting. This flaw, which was patched by Broadcom in July, allows unauthenticated attackers to execute code on vulnerable systems, which makes exposed vCenter deployments a high-value target.
VMware vCenter is a centralized management platform that helps IT admins monitor, configure, and control virtualized environments built on VMware technology. They can use vCenter to oversee multiple hosts and virtual machines from a single console, automate routine tasks, allocate computing resources, enforce security policies, and support features such as workload balancing, backup, and disaster recovery.
How can a single vCenter compromise impact entire virtual environments?
According to CISA, initial exploitation of the CVE-2026-59310 flaw was linked to threat actors deploying persistence tools for long-term access, but ransomware groups have now joined the campaign. A successful vCenter compromise can provide attackers with access to critical systems, sensitive data, and large numbers of virtual machines .
CISA recommends that organizations should immediately apply the available security updates, review internet-facing vCenter instances, and verify that systems are not already compromised. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and requires U.S. federal agencies to remediate affected systems within days.
Emergency patching can disrupt planned maintenance schedules and require accelerated testing, but delaying remediation increases the likelihood of ransomware-related incidents. It’s advised that organizations must prioritize rapid patch deployment over their normal change-management timelines.
Rabia has a master's degree in Software Engineering and she has years of experience writing professionally Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on t...
How Can Organizations Secure the Onboarding Process in 2026? Daniel Imber Last Updated: Aug 27, 2026
Last Updated: Aug 27, 2026
How Microsoft Defender Configuration Drift Leaves Endpoints Quietly Exposed Ashish Bhatti Jun 23, 2026
Passkeys Aren’t Enough: Why Enforcement Matters in Entra ID Brandon Colley Last Updated: Aug 04, 2026
Last Updated: Aug 04, 2026
The “No-Breach” Breach: How Stealer Logs Lead to Active Directory Incidents Joshua Parsons Last Updated: Jul 01, 2026
Last Updated: Jul 01, 2026
Microsoft Security Without a Rulebook: The Problem with “Require Compliant Device” Amy Babinchak Last Updated: Jul 09, 2026
Last Updated: Jul 09, 2026
Why Active Directory Password Policy Fails Modern Attacks (and What Admins Need Instead) Joshua Parsons Last Updated: Jul 01, 2026
Last Updated: Jul 01, 2026
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
