Ransomware Gangs Actively Exploiting Critical VMware vCenter RCE Vulnerability (CVE-2026-59310)
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a critical remote code execution (RCE) flaw in VMware vCenter Server. The vulnerability, tracked as CVE-2026-59310, carries a CVSS score of 9.8 and allows unauthenticated attackers with network access to the vCenter Syslog server to execute arbitrary code. Broadcom, which owns VMware, released a fix on July 29, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 18, 2026.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai