Ransomware groups are taking advantage of a critical VMware vCenter vulnerability just days after a patch was released, encrypting ESXi virtual machines and highlighting how little time defenders have to respond.
Ransomware groups have quickly seized on a newly patched VMware vCenter vulnerability, encrypting ESXi virtual machines around the world before many organizations could update their systems. The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed the attack chain, which shows just how little time defenders have to react.
Attackers outpace defenders
Within days of Broadcom releasing a patch for the CVSS 9.8 CVE-2026-59310 directory traversal bug on July 29, attackers began scanning for exposed vCenter servers. Denis Calderone, CTO of Suzu Labs, reported suspicious activity in 47 countries. At first, attackers used reverse SSH tunnels to maintain quiet access, which looked like espionage. But it quickly escalated: ransomware payloads based on Babuk started encrypting ESXi virtual machines, completing the attack cycle.
Patch-to-exploit time keeps shrinking
The timeline is tight: the patch was published on July 29, exploits were active by August 3, CISA added the bug to its known exploited vulnerabilities catalog soon after, and ransomware attacks followed almost immediately. John Strand of Black Hills Information Security points to the use of AI in exploit development as a reason for this acceleration, shrinking the gap between disclosure, patch, and real-world attacks. His advice is blunt: "Patch immediately, even if it means skipping the usual staging and testing steps."
Urgent defenses and countermeasures
Lydia Zhang, president of Ridge Security, notes that the vulnerability does not require authentication, but attackers still need network access to vCenter services. Her recommendations are practical: treat the patch as an emergency, map all vCenter instances, update right away, remove direct internet access, look for signs of compromise, isolate affected systems, preserve evidence, and rotate privileged credentials after containment.
La vulnerabilità CVE-2026-59310, classificata con un punteggio CVSS di 9.8, consente l'esecuzione di codice remoto senza autenticazione tramite una falla di directory traversal nel componente vCenter Syslog server. CISA ha imposto alle agenzie federali un termine di tre giorni per l'applicazione della patch dopo l'inserimento nel catalogo KEV, sottolineando la gravità e l'urgenza della minaccia.
Agenzia per la Cybersicurezza Nazionale (ACN), Regolatore nazionale italiano (link)
Global impact and troubling precedents
This case echoes what was previously reported on QWERTYmag: the window between patch release and active exploitation keeps shrinking, leaving companies exposed to ransomware waves that target known but unpatched vulnerabilities. Organizations that delay updates risk having their virtual machines encrypted and business data held hostage.
According to a summary from Cyber Florida, the campaign has already hit at least 361 confirmed IP addresses in 47 countries, showing the global scale of the incident and how quickly ransomware groups can exploit newly disclosed critical bugs. The attack affects not just vCenter but also the ESXi virtualization layer, making recovery especially difficult due to the risk of mass encryption of virtual machines and compromise of the entire hypervisor infrastructure.
The reality is that the lifecycle of critical vulnerabilities has shrunk to just days, sometimes hours. Traditional patching practices can no longer keep up with attackers, who now use automation and AI tools. Leaving vCenter exposed to the internet or delaying patches is no longer just bad luck-it is a choice that now amounts to leaving the door open for ransomware. For more technical details and official recommendations, see the Agenzia per la Cybersicurezza Nazionale page.