Your virtualization brain just moved from “espionage problem” to ransomware problem. CISA confirmed on September 15, 2026 that ransomware gangs have joined active exploitation of a critical VMware vCenter flaw that was supposed to be patched in July.
If vCenter still sits on a build before the fixed trains, this is not a backlog item — it is the management plane that can hand attackers every ESXi host you run.
What happened
On July 29, 2026, Broadcom patched CVE-2026-59310, a directory traversal in the vCenter Syslog server that lets an unauthenticated attacker with network access execute arbitrary code. Researchers later showed the path can write into /etc/cron.d for immediate root on the appliance.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
CISA added the bug to KEV on August 18 (federal due August 21). Campaign reporting put roughly 361 victim IPs across 47 countries in play, with Babuk-derived ransomware (.babyk) observed on ESXi hosts after vCenter compromise. Over the weekend into September 15, CISA updated KEV language to flag ransomware gang abuse — not just a single intrusion set.
Shadowserver still sees hundreds of vCenter instances exposed online. There is no public count of how many remain unpatched.
Why it matters
vCenter is the control plane for provisioning, snapshots, and host access. Compromising it is how modern ransomware skips endpoint-by-endpoint encryption and hits the hypervisor layer instead.
Unauthenticated RCE on a component that is often reachable from broad internal networks — or worse, the internet — is a blast-radius story, not a niche Syslog bug.
What to do first
- Inventory every vCenter Server Appliance. Upgrade to a fixed build: 9.1.0.0300, 9.0.2.0100, or 8.0 U3k / U2f for your train. Verify with
vpxd -v— do not trust a calendar invite that “ran updates.” - Remove internet exposure to vCenter management. Segment the management plane so it is not a casual lateral stop.
- Hunt authentication and cron anomalies since late July: malformed cron under
/etc/cron.d, unexpected reverse-SSH / webshells (Perfcharts JSP), new SSO admins, and ESXi local accounts you did not create. - Rotate vSphere SSO and service credentials tied to the compromised plane. Confirm backups and snapshots live somewhere the vCenter service account cannot delete.
- If ransomware indicators appear on ESXi (
.babykor mass encryption), isolate, preserve forensics, and treat every managed host as in-scope.
Details
- CVE: CVE-2026-59310 (CVSS 9.8)
- Product: VMware vCenter Server (Syslog server path traversal → RCE)
- KEV: Added 2026-08-18; federal due 2026-08-21; ransomware use flagged ~2026-09-15
- Fixed builds: 9.1.0.0300 · 9.0.2.0100 · 8.0 U3k / U2f
- Workarounds: None meaningful — patch and restrict network access
Hunt / verify
- Confirm build ≥ fixed train above on every appliance.
- Review crond / systemd persistence, outbound reverse shells, and unexpected SSO administrator creation since July 29.
- Cross-check ESXi host accounts and datastore encryption events against change tickets.
Sources
- BleepingComputer: CISA — vCenter RCE now exploited by ransomware gangs (Sep 15, 2026)
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-59310
- The Hacker News: Suspected China-nexus actor exploits vCenter, Babuk-derived ransomware
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.