VMware vCenter CVE-2026-59310: Ransomware Gangs Join Unauth Syslog RCE

By George Bailey   Published: 09/15/26   Updated: 09/15/26   3 min read

Your virtualization brain just moved from “espionage problem” to ransomware problem. CISA confirmed on September 15, 2026 that ransomware gangs have joined active exploitation of a critical VMware vCenter flaw that was supposed to be patched in July.

If vCenter still sits on a build before the fixed trains, this is not a backlog item — it is the management plane that can hand attackers every ESXi host you run.

What happened

On July 29, 2026, Broadcom patched CVE-2026-59310, a directory traversal in the vCenter Syslog server that lets an unauthenticated attacker with network access execute arbitrary code. Researchers later showed the path can write into /etc/cron.d for immediate root on the appliance.

CISA added the bug to KEV on August 18 (federal due August 21). Campaign reporting put roughly 361 victim IPs across 47 countries in play, with Babuk-derived ransomware (.babyk) observed on ESXi hosts after vCenter compromise. Over the weekend into September 15, CISA updated KEV language to flag ransomware gang abuse — not just a single intrusion set.

Shadowserver still sees hundreds of vCenter instances exposed online. There is no public count of how many remain unpatched.

Why it matters

vCenter is the control plane for provisioning, snapshots, and host access. Compromising it is how modern ransomware skips endpoint-by-endpoint encryption and hits the hypervisor layer instead.

Unauthenticated RCE on a component that is often reachable from broad internal networks — or worse, the internet — is a blast-radius story, not a niche Syslog bug.

What to do first

Details

Hunt / verify

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.