Ransomware Gangs Now Exploiting Critical VMware vCenter Flaw That Hit 361 IPs
CISA updated its Known Exploited Vulnerabilities catalog in September 2026 to confirm ransomware gangs are actively abusing CVE-2026-59310, a CVSS 9.8 VMware vCenter path-traversal flaw that allows unauthenticated remote code execution. Incident responders had already tracked exploitation to 361 victim IP addresses across 47 countries, with attackers deploying the reverse_ssh persistence framework within five days of Broadcom's July 29 disclosure. No specific ransomware group, named victim, or vendor-published indicators of compromise have been confirmed in reviewed sources.