CYBER DELTA FORCESearch

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.

CDF News DeskBleepingComputer15 Sept 2026, 5:46 pm
Image courtesy of BleepingComputer. Original report
CDF REPORT

Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days. Over the weekend, CISA updated its KEV catalog again to flag the security vulnerability as actively abused by ransomware gangs . Internet security threat monitor Shadowserver currently tracks over 450 VMware vCenter servers exposed online ; however, there is no information on how many have already been patched against this flaw.

CISA also warned in February that ransomware groups began exploiting a VMware ESXi sandbox escape vulnerability (CVE-2025-22225), which Chinese-speaking threat actors have targeted in zero-day attacks since at least February 2024.

What changed

Since the start of the year, the cybersecurity agency has also flagged VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) flaws as exploited in attacks in February and March.

Over the last five years, CISA has tagged 26 VMware vulnerabilities as exploited in the wild, nine of them also abused by ransomware operations.

Why this matters

CISA also warned in February that ransomware groups began exploiting a VMware ESXi sandbox escape vulnerability (CVE-2025-22225), which Chinese-speaking threat actors have targeted in zero-day attacks since at least February 2024.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.

MORE IN RANSOMWARE

More cybersecurity reporting

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwareThe Hacker News · 11 Sept 2026, 11:49 amVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate DataDark Reading · 11 Sept 2026, 2:06 amTwo Alleged ‘TeamPCP’ Hackers Arrested in AustraliaKrebsOnSecurity · 27 Aug 2026, 4:34 pmCanadian Man Pleads Guilty in Snowflake ExtortionsKrebsOnSecurity · 6 Aug 2026, 10:30 pm