CVE-2026-59310 — a critical directory traversal flaw in the VMware vCenter Syslog server patched on July 29 — is now being actively exploited by ransomware gangs, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned.
Broadcom's July 29 patch and the emergency alert
Broadcom disclosed CVE-2026-59310 on July 29 and described it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code. At the time of the patch release, Broadcom warned customers in a supplemental FAQ to treat fixing CVE-2026-59310 as an emergency and to install patches as soon as possible.
QUIRSO's findings: 361 IP addresses across 47 countries
Two weeks after the patch, digital forensics and incident response company QUIRSO reported that it had found more than 361 IP addresses across 47 countries compromised by what it identified as exploitation of CVE-2026-59310. QUIRSO said the suspected attacker — characterized in its reporting as an advanced persistent threat actor — deployed a reverse SSH tool to establish persistence and remote access on affected systems.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCISA's escalation: KEV listing, three-day government order, and ransomware designation
CISA responded by adding CVE-2026-59310 to its Known Exploited Vulnerabilities (KEV) Catalog and ordered government agencies to secure their vCenter systems within three days. Over the following weekend, CISA updated the KEV catalog again to flag the vulnerability as actively abused by ransomware gangs. The agency has not, in its public note cited in the reporting, provided technical details of the ransomware incidents themselves.
Exposure tracked by Shadowserver and why VMware targets matter
Internet security monitor Shadowserver currently tracks more than 450 VMware vCenter servers exposed online. The public reporting notes there is no information available on how many of those exposed servers have been patched against CVE-2026-59310. CISA's bulletin underscores why VMware components are attractive targets: compromised vCenter or ESXi servers can provide attackers access to an organization's internal network and to sensitive data stored on internal systems.
The advisory also placed CVE-2026-59310 in a longer pattern of VMware-focused exploitation. CISA had previously warned in February that ransomware groups were exploiting an ESXi sandbox escape vulnerability, CVE-2025-22225, which it said Chinese-speaking threat actors had targeted in zero-day attacks since at least February 2024. Since the start of the year, the agency also flagged exploitation of VMware Aria Operations (CVE-2026-22719) and VMware vCenter Server (CVE-2024-37079) in February and March. Over the last five years, CISA has tagged 26 VMware vulnerabilities as exploited in the wild, nine of them also abused by ransomware operations.
What this means for technologists, government agencies, and enterprises
- Technologists and security teams: Broadcom's supplemental FAQ urged treating the fix as an emergency; the public record here shows active exploitation and deployment of a reverse SSH tool, so teams will be watching for signs of persistence and applying vendor patches as a priority.
- Government agencies: CISA ordered agencies to secure vCenter systems within three days and has now flagged the vulnerability as actively abused by ransomware gangs — a clear, time-bound directive in federal systems context.
- Enterprises and IT procurement leaders: With more than 450 vCenter servers observed exposed online and no public tally of how many have been patched, organizations that use VMware tooling are named explicitly as high-risk in this advisory cycle, particularly because multiple ransomware operations have developed encryptors that target VMware virtual machines.
Conclusion: The record in public reporting is straightforward and stark: a vendor patch released on July 29 for CVE-2026-59310 was followed by observed exploitation and a rapid escalation from a DFIR company’s compromise tally to CISA’s emergency KEV listing and a specific warning that ransomware gangs are abusing the flaw. What remains unanswered in the public notice is how many internet-exposed vCenter servers have actually been patched; until that number is known, the combination of active exploitation, observed reverse SSH persistence, and a sizable population of exposed systems leaves organizations with a narrow window to act.




