Skip to content
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310

Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310

First seen 15 Sep 2026, 18:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 19:55 UTC
  • CVE-2026-59310 is a critical vulnerability in VMware vCenter with a CVSS score of 9.8.
  • Ransomware gangs are actively exploiting this flaw, increasing risks for unpatched systems.
  • CISA has mandated a three-day patching deadline for federal agencies to secure affected systems.

On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access to execute arbitrary code. Broadcom issued a patch for this vulnerability on July 29, 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026. Organizations running affected vCenter instances are urged to prioritize patching as the exploitation can lead to access to critical systems and sensitive data. Initial exploitation was linked to persistent access tools, but ransomware groups have now joined the attack vector. CISA has mandated federal agencies to secure their systems within three days of the advisory. The vulnerability's exploitation could potentially impact hundreds of virtual machines in enterprise environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-09-23
CVE-2021-22005 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-06-18
CVE-2024-37079 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-03-04
CVE-2025-22226 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-03-04
CVE-2025-22225 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-11-11
CVE-2025-60710 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-25
CVE-2026-22719 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-29
Broadcom patches CVE-2026-59310
Broadcom released a fix for the critical remote code execution vulnerability in VMware vCenter.
Shattered
2026-07-30
CVE-2026-59309 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-59310 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, indicating active exploitation.
Bleepingcomputer
2026-09-15
CISA confirms ransomware exploitation
CISA confirmed that ransomware gangs are exploiting CVE-2026-59310, urging immediate patching.
Tech-Insider

More articles in this cluster (5)

Following this threat?

Track CVE-2021-22005 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed