Ransomware Gangs Actively Exploiting Critical VMware vCenter RCE Vulnerability (CVE-2026-59310)

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-15T19:01:08Z
Category: technology
Source: shattered.io

The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are now actively exploiting a critical remote code execution (RCE) flaw in VMware vCenter Server. The vulnerability, tracked as CVE-2026-59310, carries a CVSS score of 9.8 and allows unauthenticated attackers with network access to the vCenter Syslog server to execute arbitrary code. Broadcom, which owns VMware, released a fix on July 29, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 18, 2026.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai