Ransomware Exploits vCenter; CISA Issues Alert in 47 Nations

The agency confirmed that ransomware gangs joined espionage efforts exploiting CVE-2026-59310 in vCenter's Syslog component.
CISA updated its advisory on September 15 regarding CVE-2026-59310, a directory traversal vulnerability in the Syslog service of VMware vCenter Server with a CVSS score of 9.8. The agency confirmed that ransomware gangs have begun exploiting the vulnerability alongside an ongoing espionage campaign that has been active since July, when Broadcom released the patch on July 29. The initial reach mapped by incident responders spans 361 compromised IP addresses across 47 countries.
The affected component allows an unauthenticated attacker with network access to execute arbitrary code on the server without special privileges. The CVE was added to the Known Exploited Vulnerabilities Catalog on August 18, and Binding Operational Directive 26-04 mandated remediation by federal agencies by August 21. The change now is in the vector: where there was previously silent capture of SSO credentials and deployment of a persistent backdoor, a chain oriented toward mass encryption of ESXi hypervisors appears.
From Espionage to Extortion
According to incident response reports cited by CISA, attackers use Syslog to deposit persistent code in vCenter, capture single sign-on credentials, and then execute variants derived from Babuk against the ESXi layer. The choice is technical: whoever controls vCenter gains access to the entire fleet of virtual machines running beneath it. A single compromised administrator becomes a gateway to dozens of encrypted servers in minutes.
The affected product includes vSphere Foundation in all versions, Cloud Foundation, Telco Cloud Infrastructure 3.0, Telco Cloud Platform, and vCenter Server 8.0 up to update 3j. This encompasses the installed stock in corporate data centers, telecom providers, and healthcare environments worldwide, helping to explain why investigators have found victims in 47 countries.
Insights for CIOs in Three Markets
In the United States, where vCenter remains the backbone of regional banks and healthcare systems, the issue is operational before it is regulatory: HIPAA and SEC will require notification within short timelines as soon as there is encryption of protected data. In telecom providers in India and Europe that still maintain Telco Cloud Infrastructure in production, the patch encounters scheduled maintenance windows set months in advance for critical network infrastructure. In Brazil, where banks and Serpro operate large ESXi fleets behind vCenter, the vector aligns with the timetable of Circular BCB No. 4,041, which requires control and reporting of significant cyber incidents within two hours—an alarmingly short timeframe to ascertain the extent of mass encryption.
Broadcom continues to advise applying the patch from July 29 and temporarily disabling Syslog on instances that cannot undergo immediate downtime. EDR vendors reported that behavior signatures indicating pre-encryption probing via Syslog followed by SSO credential reading are detectable even before the ransomware reaches ESXi. Not all SOC teams, however, operate specific rules for vCenter.
The Economic Rearrangement of Ransomware Over Virtualization
The vCenter case confirms a pattern that has been developing for two years. Gangs have partially abandoned targeting corporate workstations in favor of the hypervisor layer, where a successful attack paralyzes production without requiring extensive lateral movement. Groups like RansomHub, Reformed LockBit, and the Babuk clone now operate with specialized playbooks for ESXi, and the time lag between disclosure and mass exploitation continues to shrink. Less than seven weeks passed from the patch release by Broadcom on July 29 to the mark of 361 compromised IPs.
The boundary between state operations and organized crime for financial gain is also increasingly blurred. The initial campaign against CVE-2026-59310 was attributed by Gurucul researchers to an actor with Chinese ties focused on espionage. The entry of financial gangs into the same vector suggests that the technical intelligence for exploitation quickly leaks from the APT environment to initial access broker forums. For corporate CISOs, the practical implication is clear: the interval between patch and ransomware needs to be counted in days, not months.
There is a budgetary subtext. Broadcom, which absorbed VMware in 2023 for $61 billion and restructured licensing around vSphere Foundation, pushes parts of the installed base towards more recent versions where the patch is already integrated. Clients who negotiated discounts for extended maintenance to stay on vCenter 7.0 are exposed, and the decision to accelerate upgrades clashes with capex approval cycles that often stretch over quarters. The window between acknowledging the risk and obtaining authorization to spend remains the most vulnerable point in the corporate response cycle.