CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Cybersecurity · September 16, 2026

Cybersecurity·bleepingcomputer.com

CISA has issued a fresh alert warning that ransomware operators have joined the list of threat actors abusing a critical remote-code-execution bug in VMware vCenter Server. The flaw, patched back in July, was already under active attack by other groups before ransomware gangs began exploiting it too. CISA is urging any organization still running unpatched vCenter deployments to apply the fix without delay.

// source: bleepingcomputer.com ↗

Back to Blog