Shattered Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310
Article Content
- •CVE-2026-59310 is a critical vulnerability in VMware vCenter with a CVSS score of 9.8.
- •Ransomware gangs are actively exploiting this flaw, increasing risks for unpatched systems.
- •CISA has mandated a three-day patching deadline for federal agencies to secure affected systems.
On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access to execute arbitrary code. Broadcom issued a patch for this vulnerability on July 29, 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026. Organizations running affected vCenter instances are urged to prioritize patching as the exploitation can lead to access to critical systems and sensitive data. Initial exploitation was linked to persistent access tools, but ransomware groups have now joined the attack vector. CISA has mandated federal agencies to secure their systems within three days of the advisory. The vulnerability's exploitation could potentially impact hundreds of virtual machines in enterprise environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2021-22005 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…