Ransomware gangs exploit VMware control systems to reach enterprise data
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 16th, 2026.
Enterprise virtualization environments now have a confirmed ransomware path through VMware vCenter. CISA says ransomware gangs have joined ongoing attacks against a critical directory-traversal issue that Broadcom patched on July 29th. An unauthenticated attacker can abuse the vCenter Syslog server to execute arbitrary code. Earlier incident-response work identified more than 361 compromised I P addresses across 47 countries, and more than 450 vCenter servers were still being tracked as exposed to the internet.
This matters because vCenter can provide reach into virtual machines and sensitive internal data. A compromise at that control layer may spread across many workloads and turn into a much larger recovery problem. Leaders should treat virtualization management as critical business infrastructure rather than another routine server. Defenders should verify fixed versions, reduce internet exposure, and look for reverse S S H or unexpected administrative activity. It’s still unclear how many exposed systems have been patched, so the safest course is to patch every affected vCenter system immediately and investigate any instance that remained unpatched.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.