MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-15 · via BleepingComputer

Ransomware groups escalate attacks on unpatched VMware vCenter servers

Image via BleepingComputer
Image via BleepingComputer

The U.S. cybersecurity agency has added a critical VMware vCenter vulnerability to its known exploited list after ransomware operators began using it. The flaw, patched in July, allows unauthenticated attackers to execute arbitrary code via a directory traversal in the vCenter Syslog server. More than 450 vCenter servers remain exposed online, and government agencies were ordered to patch within three days.

Expanded Detail

The vulnerability, patched by Broadcom in late July, enables unauthenticated code execution through a directory traversal flaw in the vCenter Syslog component. Digital forensics firm QUIRSO documented over 360 compromised IP addresses across 47 countries, with attackers deploying reverse SSH tools for persistent remote access before ransomware groups joined the campaign.

VMware infrastructure remains a prime target because vCenter and ESXi servers act as central management points for enterprise virtual machines and sensitive corporate data. CISA has now cataloged 26 VMware flaws exploited in the wild over five years, with nine of those abused by ransomware operations. Shadowserver currently identifies more than 450 vCenter servers still exposed online, though patch status remains unclear.

Context

Organizations relying on VMware vCenter for virtualized infrastructure could face significant operational disruption if compromised, as ransomware operators may encrypt virtual machines and demand payment for recovery. Government agencies, enterprises, and managed service providers are particularly exposed, given the three-day patching mandate and the hundreds of servers still visible online. The cascading effect of a vCenter breach could extend beyond immediate data loss to prolonged downtime, affecting business continuity and potentially critical services that depend on virtualized environments.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Ransomware Gangs Join Attacks on Unpatched WatchGuard Fireboxes · Cybersecurity
Cisco fixes actively exploited email gateway flaw allowing root access · Cybersecurity
CISA flags active exploitation of critical GitLab vulnerability · Cybersecurity
Cisco warns of active exploitation of critical firewall management flaw · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “CISA: Critical VMware RCE flaw now exploited by ransomware gangs.” Browse more stories.