Critical VMware vCenter RCE (CVE‑2026‑59310) Actively Exploited by Ransomware Gangs, CISA Warns
What Happened – CISA announced that ransomware groups are now leveraging the critical VMware vCenter directory‑traversal flaw (CVE‑2026‑59310) that allows unauthenticated code execution. The vulnerability was patched on July 29 2026, but threat actors have already compromised hundreds of vCenter instances worldwide, using reverse‑SSH tools for persistence.
Why It Matters for Trust & Control Assurance
- Unpatched critical flaws break the “continuous control‑assurance” promise that organizations must demonstrate timely remediation of high‑severity vulnerabilities.
- Evidence of patch deployment, configuration validation, and ongoing monitoring becomes essential audit artifacts to prove due‑diligence.
- The incident underscores the need for a control‑mapping capability that ties vulnerability remediation to multiple frameworks in a single, defensible evidence set.
Who Is Affected – Cloud‑infrastructure providers, data‑center operators, and any enterprise that runs VMware vCenter or ESXi workloads (e.g., finance, healthcare, SaaS, manufacturing).
Recommended Actions – Verify that the July 2026 patch for CVE‑2026‑59310 is applied on every vCenter instance, generate immutable remediation logs, and integrate continuous vulnerability‑scan results into your control‑mapping dashboard for audit readiness. Source: BleepingComputer
Technical Notes – The flaw is a critical directory‑traversal vulnerability in the vCenter Syslog service that enables remote code execution without authentication (CVSS 9.8). Exploitation has been observed in 47 countries, with ransomware actors deploying reverse‑SSH payloads for persistence. Source: CISA KEV Catalog