CuraSec

Act active

CISA: VMware vCenter RCE actively exploited by ransomware gangs

2026-09-15 15:32 UTC · BleepingComputer · read the source ↗ #vmware-vcenter#ransomware#rce
  • Engineer — Act: VMware vCenter is core enterprise infrastructure and this RCE is under active ransomware exploitation per CISA — patch vCenter to the July-released fix immediately if not already done, and verify patch status across all vCenter instances in your environment.
  • SOC/IR — Act: Ransomware actors are exploiting vCenter in the wild — run a retrospective hunt across vCenter logs since July for signs of exploitation or lateral movement, and verify EDR coverage on vCenter hosts where possible.
  • Leader — Act: CISA-confirmed ransomware exploitation of a widely deployed infrastructure component warrants same-week action — confirm with your engineering team that vCenter instances are patched and brief leadership given the ransomware-as-operational-risk angle.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.