vCenter's Syslog Bug Has Moved From Quiet Persistence to Ransomware
CISA now flags CVE-2026-59310 as used in ransomware campaigns; if your vCenter was exposed and unpatched this summer, patching is the start of the job, not the end.
CISA has updated its Known Exploited Vulnerabilities catalogue to say that ransomware gangs are now exploiting CVE-2026-59310, a critical flaw in VMware vCenter. BleepingComputer reported the change on 15 September. Earlier this summer the exploitation was attributed to a suspected advanced persistent threat actor; ransomware operators have now joined in. It is a directory traversal in the vCenter Syslog server that gives unauthenticated attackers code execution. Broadcom patched it on 29 July and there is no workaround.
Six weeks of exploitation
Exploitation started almost immediately. Forensics firm QUIRSO saw the first attacks on 3 August, five days after the patch, and 151 new victim IPs on 4 August alone. By 7 August it had counted 361 compromised IP addresses across 47 countries, with Germany, the US, Turkey, Iran and France the most affected. Those attackers installed the open-source reverse_ssh framework for persistence. That tool calls out from the compromised host, so inbound firewall rules do little to stop it. CISA added the flaw to KEV on 18 August with a three-day deadline for federal agencies.
Shadowserver still sees more than 450 vCenter servers exposed to the internet, and nobody knows how many of them are patched.
Why ransomware crews love this
vCenter is the control plane for a whole estate. Compromising it gives an attacker every host and every VM, and many ransomware families now ship Linux encryptors written specifically for VMware environments. One foothold in vCenter can mean encrypting the datastores underneath hundreds of machines at once, without touching a single guest OS where your endpoint agents run. If your backup appliance is also a VM managed by that vCenter, you can see how a bad week becomes a very bad quarter.
The question I keep asking is why 450 vCenter instances are reachable from the internet at all. vCenter is a management interface. It belongs behind a VPN or a bastion host, on a network that ordinary workloads cannot reach. Every exposed instance is a decision someone made, or forgot to undo, and this bug is what turns that decision into an incident.
What to do now
- Patch to the fixed builds: 9.1.0.0300 for vCenter 9.1, 9.0.2.0100 for 9.0, and 8.0 U3k or U2f for 8.0.
- Assume compromise if you were exposed. If the Syslog service was reachable from untrusted networks at any point after 29 July, patching only closes the door. Look for
reverse_sshor other unexpected outbound SSH from the appliance, new local accounts, and changes to services or cron. QUIRSO has withheld some indicators pending law-enforcement work, so do not treat an empty match against public IOCs as proof you are clean. - Take vCenter off the internet, and limit which internal networks can reach its management and Syslog ports.
- Check your recovery path. Make sure at least one backup copy is not reachable from the virtualisation management plane, and that you have actually restored from it this year.
What is still unclear
CISA's update does not name the ransomware groups, and nobody has said publicly whether they are reusing access from the August campaign or exploiting the bug fresh. That distinction matters. If footholds are being resold, organisations that patched promptly in August but never hunted could still be hit. Also, QUIRSO's APT attribution came without supporting evidence, so be careful with any threat-intel feed that presents it as settled.
The broader pattern is depressingly familiar. A virtualisation management bug is patched, exploited within a week, and then handed down to ransomware crews within two months. Plan for that timeline next time, because there will be a next time.
Sources