Ransomware groups escalate attacks on unpatched VMware vCenter servers

The U.S. cybersecurity agency has added a critical VMware vCenter vulnerability to its known exploited list after ransomware operators began using it. The flaw, patched in July, allows unauthenticated attackers to execute arbitrary code via a directory traversal in the vCenter Syslog server. More than 450 vCenter servers remain exposed online, and government agencies were ordered to patch within three days.
The vulnerability, patched by Broadcom in late July, enables unauthenticated code execution through a directory traversal flaw in the vCenter Syslog component. Digital forensics firm QUIRSO documented over 360 compromised IP addresses across 47 countries, with attackers deploying reverse SSH tools for persistent remote access before ransomware groups joined the campaign.
VMware infrastructure remains a prime target because vCenter and ESXi servers act as central management points for enterprise virtual machines and sensitive corporate data. CISA has now cataloged 26 VMware flaws exploited in the wild over five years, with nine of those abused by ransomware operations. Shadowserver currently identifies more than 450 vCenter servers still exposed online, though patch status remains unclear.
Organizations relying on VMware vCenter for virtualized infrastructure could face significant operational disruption if compromised, as ransomware operators may encrypt virtual machines and demand payment for recovery. Government agencies, enterprises, and managed service providers are particularly exposed, given the three-day patching mandate and the hundreds of servers still visible online. The cascading effect of a vCenter breach could extend beyond immediate data loss to prolonged downtime, affecting business continuity and potentially critical services that depend on virtualized environments.