Broadcom patched CVE-2026-59310, a CVSS 9.8 directory traversal in vCenter Server's Syslog component, on 29 July as part of advisory VMSA-2026-0006. CISA added it to its exploited-vulnerabilities catalog on 18 August after a suspected China-nexus actor was caught using it to plant a remote-access implant, and gave federal agencies a three-day deadline. By the time we wrote about it, a digital forensics firm had already counted 361 compromised IP addresses spread across 47 countries - a scale that made it one of the year's fastest-moving vCenter campaigns. What CISA's 15 September catalog update adds is a change of actor, not a change of bug: the same unpatched flaw is now confirmed in the hands of ransomware operators who have nothing to do with the original espionage push.
What actually changed between August and now
The August exploitation had a fairly specific shape - a single suspected state-linked group, an implant built for persistence and access rather than immediate disruption, and no ransom note in sight. CISA's language for the 15 September update drops that framing entirely, describing the vulnerability as "actively abused by ransomware gangs" without naming a specific group or attributing it to a nation-state operator. That's the pattern security teams should recognise from plenty of prior CVEs, and it's exactly what BleepingComputer's reporting on the update lays out: an espionage actor proves a bug is exploitable and worth the effort, and once that proof exists in the wild - whether through leaked tooling, independent discovery or simple imitation - opportunistic ransomware crews follow the same path with none of the original group's restraint about staying quiet.
The exposure hasn't meaningfully shrunk
Seven weeks after Broadcom's patch, Shadowserver's scans still show more than 450 vCenter servers reachable from the open internet. vCenter is not supposed to be an internet-facing service in a well-run environment - it's the management plane for an organisation's entire virtualisation estate, which is exactly why both an espionage actor and a ransomware crew would want a foothold in it rather than in any single virtual machine. A directory traversal bug in vCenter's Syslog handling giving unauthenticated remote code execution means anyone who can reach that management interface, patched host security elsewhere notwithstanding, can potentially reach every VM it manages in one move.
Why this sequence matters more than the CVE itself
Our original coverage flagged Babuk-derived ransomware already turning up on some compromised ESXi hosts during the August wave - so the ransomware angle isn't brand new information on its own. What's new is CISA formally confirming, through its own catalog language, that the threat picture has broadened past a single attributed actor into a wider criminal ecosystem actively working the same unpatched population. For any organisation that read the August news, filed it under "targeted espionage, probably not us" and moved on, this update is the correction: an unpatched vCenter instance is now a target for whoever gets there first, state-linked or not.
- Treat any internet-reachable vCenter, or any management-plane system, as a standing incident regardless of who is currently known to be exploiting the underlying CVE - attribution changes faster than patch cycles do.
- Confirm CVE-2026-59310 is patched to vCenter 9.1.0.0300, 9.0.2.0100 or 8.0 U3k/U2f, and don't rely on "we saw no scanning" as evidence of safety this many weeks after public exploitation began.
- Pull vCenter and other management interfaces off the open internet entirely where possible, and place them behind VPN or jump-host access with logging that would catch a Syslog-handler exploit attempt.
- Revisit any risk assessment that downgraded this CVE because the known exploitation looked narrowly targeted - CISA's own catalog language for this bug has now changed once already.
- Check ESXi hosts managed by any previously exposed vCenter instance for Babuk-derived or other unfamiliar ransomware payloads, not just for signs of the original espionage implant.
A management-plane bug doesn't stay any one group's secret for long, and the gap between "an APT is using this" and "ransomware crews are using this too" is often measured in weeks. If you'd like a straight assessment of what's still reachable in your own vCenter estate, email sales@halfteck.com.