VMware vCenter Syslog flaw exploited at scale and by ransomware (CVE-2026-59310)
Attackers began exploiting CVE-2026-59310, a critical unauthenticated remote code execution flaw in the VMware vCenter Syslog server, days after Broadcom patched it, compromising more than 360 systems in 47 countries; CISA later flagged the bug as used in ransomware campaigns.
- Victim
- VMware vCenter Server (Broadcom)