CISA: Critical VMware vCenter RCE Now Exploited
🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that ransomware gangs are now exploiting a critical VMware vCenter vulnerability (CVE-2026-59310) patched by Broadcom on July 29. The flaw is a directory traversal issue in the vCenter Syslog server that allows unauthenticated attackers to execute arbitrary code; Broadcom urged emergency patching. Security firms reported widespread compromises and CISA added the CVE to its KEV Catalog, ordering rapid remediation across government systems.
