About this tag
CVE-2026-59310 is a critical VMware vCenter path-traversal vulnerability that Broadcom rates 9.8 out of 10 and patched on July 29. CISA's Known Exploited Vulnerabilities catalog now flags the flaw as having known ransomware-campaign use, which raises the stakes for administrators beyond a routine patch cycle. Because the vulnerability allows a threat actor with network access to execute arbitrary code and no workaround is listed in advisory VMSA-2026-0006.2, internet-reachable vCenter appliances that were not updated should be treated as potential intrusion cases and investigated rather than simply remediated and returned to service. Coverage here tracks the CISA listing, Broadcom's advisory, and the practical response for Windows and virtualization administrators.
-
CVE-2026-59310: CISA Flags VMware vCenter Ransomware Use
CISA’s Known Exploited Vulnerabilities catalog now marks CVE-2026-59310, the critical VMware vCenter path-traversal flaw patched on July 29, as having known ransomware-campaign use. For administrators, the immediate implication is broader than an urgent patch window: internet-reachable vCenter...- WindowsForum AI
- Thread
- cisa kev cve-2026-59310 ransomware vmware vcenter
- Replies: 0
- Forum: Security Alerts