Skip to content

Security1 publisher2 min readPublished

Ransomware gangs move onto the vCenter Syslog bug Broadcom patched on July 29

CVE-2026-59310 gave a suspected APT crew persistence on vCenter systems in August. CISA has now flagged the same directory traversal as abused by ransomware operators. Broadcom patched it on July 29.

The Watch · Security desk

Illustration accompanying Ransomware gangs move onto the vCenter Syslog bug Broadcom patched on July 29

What happened

  • Digital forensics firm QUIRSO reported two weeks later that a suspected APT actor had compromised more than 361 IP addresses across 47 countries, planting a reverse SSH tool for persistence and remote access.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog days after that report and ordered government agencies to secure their vCenter systems within three days.
  • CISA updated the same catalog over the weekend to mark CVE-2026-59310 as actively abused by ransomware gangs, and has not published details of those attacks.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure One unauthenticated request against the management plane can put an entire virtual estate in scope for encryption, and an affiliate who lands on vCenter does not have to hunt laterally for where the data sits.
  • decision Anyone who deferred the vCenter reboot in July on the reasoning that espionage targeting is selective now has to schedule it against opportunistic crews who encrypt whatever they reach.
  • precedent On CISA's own tally, roughly a third of exploited VMware bugs end up in ransomware hands, so the sensible default for a pre-auth VMware flaw is to plan for encryption from day one rather than wait for the catalog to confirm it.
  • constraint Patch state for vCenter is not disclosed, so a defender sizing the wider exposure works from a count of internet-facing servers and cannot tell how many of them are fixed.

The flaw is a directory traversal in the vCenter Syslog server, and Broadcom's description says an unauthenticated attacker can use it to execute arbitrary code [1]. vCenter sits above the ESXi estate. A compromised vCenter or ESXi server can hand an intruder access to an organisation's network and to data held on internal systems [8], and multiple ransomware crews have built encryptors specifically for VMware virtual machines, because that is where enterprises keep corporate data [9].

QUIRSO's report came about two weeks after the July 29 patch, so around August 12, and CISA's catalogue entry followed within days. Roughly three weeks separated the fix from a three-day remediation deadline for federal agencies [14].

Shadowserver currently tracks more than 450 vCenter servers exposed online [7]. QUIRSO's compromised-host count is about 80 per cent of that exposed population [15]. The two figures measure different things at different times, and both readings are uncomfortable: either far more vCenters were reachable in August than a scan finds now, or a large share of the hosts QUIRSO identified have since come off the public internet.

The pattern around VMware is established. CISA has tagged 26 VMware vulnerabilities as exploited in the wild over the last five years, and nine of those were also abused by ransomware operations [12], about one in three [13]. In February the agency said ransomware groups had begun exploiting the ESXi sandbox escape CVE-2025-22225, a bug Chinese-speaking threat actors had used in zero-day attacks since at least February 2024 [10]. It flagged VMware Aria Operations (CVE-2026-22719) and vCenter Server (CVE-2024-37079) as exploited in February and March [11].

Broadcom's instruction has not changed since July. The supplemental FAQ published with the fix told customers to treat CVE-2026-59310 as an emergency and install patches as soon as possible [2]. The weekend update changes who arrives next on an unpatched host. A reverse SSH implant is a persistence problem found on review [3]; an affiliate with a VMware encryptor runs it on first access [9].

What to watch

  • Whether CISA names the ransomware groups or publishes post-exploitation indicators for CVE-2026-59310.
  • Whether Shadowserver's exposed vCenter count moves, and whether anyone publishes patch-state data for the population.
  • Whether the reverse SSH access QUIRSO found on 361 hosts turns up in ransomware intrusions, which would tie the two waves together.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories