Tag: cve 2026 59310
7 articles

Ransomware gangs exploit VMware flaw
Ransomware gangs are actively exploiting a critical VMware flaw, CVE-2026-59310, that was patched just two weeks ago, putting organizations at risk of devastating attacks. The US Cybersecurity and Infrastructure Security Agency has warned of the vulnerability, which allows unauthenticated attackers to execute arbitrary code.

China APT Exploits VMware Flaw in Targeted Attacks
A recent investigation revealed that a suspected China-nexus APT group is actively exploiting a critical VMware vCenter vulnerability, CVE-2026-59310, to execute arbitrary code and deploy a backdoor, with ransomware seemingly used as a smokescreen to distract from the underlying intrusion. The attackers' true intentions appear to go beyond mere ransomware deployment.

China-nexus APT Exploits VMware Flaw to Deploy Ransomware
A China-linked APT group has been exploiting a recently patched VMware vCenter vulnerability to deploy ransomware in a widespread campaign that hit 361 victims across 47 countries. The attackers used the flaw to gain root access and, in some cases, installed a Babuk-derived ransomware that locks files with a ".babyk" extension.

VMware vCenter flaw exploited for reverse SSH access globally
A critical VMware vCenter flaw, CVE-2026-59310, is being exploited globally, with 361 Internet-connected systems across 47 countries already compromised. This severe vulnerability allows unauthenticated attackers to execute arbitrary code, making swift action essential to prevent further breaches.

VMware vCenter Flaw Exploited Days After Disclosure
Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.

VMware vCenter Vulnerability Exploited for Persistent Remote Access
Hackers are quickly exploiting a high-severity vulnerability in VMware vCenter, using it to gain persistent remote access to affected systems, with evidence of attacks emerging just days after patches were released. This alarming timeline suggests that publicly disclosing vulnerabilities can sometimes inadvertently hand attackers a roadmap for exploitation.

Broadcom Disrupts VMware with Emergency Patches for Critical Flaws
Broadcom has just released emergency security patches to tackle critical flaws in VMware's vCenter, ESX, Workstation, and Fusion - and it's urging admins to act fast, treating affected systems as immediately vulnerable. Three critical vulnerabilities, including CVE-2026-59309, CVE-2026-59310, and CVE-2026-47876, are among the five patched across these products and others that contain vCenter or ESX.