The Deadline Was August. The Ransomware Came In September.
This week CISA told security teams that ransomware gangs have joined the attacks on a VMware vCenter vulnerability that Broadcom patched on 29 July. The fix has existed for nearly seven weeks. The federal deadline to apply it was 21 August. The flaw, CVE-2026-59310, lets an unauthenticated attacker run code as root on the vCenter appliance, the single console that manages an organisation's entire virtual estate. Ransomware operators do not usually arrive seven weeks after a patch ships unless enough targets are still unpatched to make it worth their time. The story here is not a new vulnerability. It is that a passed deadline is being treated as a closed risk, and it is not one.
Most organisations that run VMware will read the word "patch" and stop. The reason this belongs in front of a leadership team is what the vulnerable device is. vCenter is not another server in the rack. It is the control plane: the console that configures every ESXi hypervisor, holds the credentials to the identity domain, and can reach every virtual machine in the estate at once. An attacker with root on it does not have a foothold. They have the keys to everything the virtualisation platform runs. In the intrusion QUIRSO documented in detail, that access ended in ransomware on the hypervisors themselves.
What happened
The facts below are drawn from Broadcom's advisory, CISA's catalogue, the CVE record, and the incident analysis published by the German response firm QUIRSO.
- 29 July 2026Broadcom publishes VMSA-2026-0006. It fixes five issues, including two critical, unauthenticated, remotely exploitable flaws in vCenter: CVE-2026-59310, a directory traversal in the vCenter syslog server that leads to code execution as root, and CVE-2026-59309, an authentication bypass in the VMware Directory Service. Both score CVSS 9.8. There is no workaround. Broadcom's own guidance calls fixing them an emergency change. Fixed builds are vCenter 9.1.0.0300, 9.0.2.0100 and 8.0 U3k, with an 8.0 U2f express patch added on 3 August.
- 3 August 2026Five days after disclosure, QUIRSO observes the first compromised systems calling attacker infrastructure. The actor exploits the syslog server to write a malformed cron file into a privileged directory, which runs as root and fetches a backdoor. QUIRSO notes that exploitation began before it was aware of any public proof of concept.
- 3 to 7 August 2026The campaign expands to 361 unique victim IP addresses across 47 countries, roughly 95% of them appearing within two days. Germany, the United States, Turkey, Iran and France account for 185 of the 361, just over half. QUIRSO cautions that one IP does not necessarily map to one organisation.
- 18 August 2026CISA adds CVE-2026-59310 to its Known Exploited Vulnerabilities catalogue and, under Binding Operational Directive 26-04, orders federal civilian agencies to act by 21 August.
- 13 to 14 September 2026Over the weekend CISA updates the catalogue entry to flag CVE-2026-59310 as now used in ransomware campaigns. BleepingComputer reports the update on 15 September. CISA has not published details of the ransomware activity or named victims. Shadowserver continues to track more than 450 exposed vCenter servers online.
Why this one is different
Critical vulnerabilities in enterprise infrastructure are a weekly event. Three things lift this one above the noise.
The target is the control plane, not an endpoint. Most vulnerability advisories concern a device that does one job. vCenter runs the estate. Compromise it and the attacker inherits the identity domain, every hypervisor and every virtual machine at once. In the case QUIRSO documented in detail, the actor used root on the appliance to read the vCenter machine account and single sign-on domain, created domain administrator accounts, pivoted to the ESXi hosts, and deployed a Babuk-derived ransomware that encrypted the virtual machine datastores and removed the vSphere high-availability agent to hinder recovery. The blast radius of one unpatched box was the whole virtual environment.
The patch is old and the exploitation is fresh. Ransomware operators joining nearly seven weeks after a fix is published is a signal about the defender population, not the attacker. It says the pool of unpatched, reachable vCenter servers is still large enough to be commercially worthwhile. A vulnerability that was an emergency in late July has become, for the organisations that did not act, a slow-moving certainty in September. The internal deadline that was met on paper and missed in practice is exactly where these servers sit.
Patching does not evict an intruder who is already in. Jason Soroko of Sectigo made the point plainly on a related VMware disclosure: there are two clocks to manage, one for closing the vulnerability and one for removing anyone who entered before the patch. QUIRSO found the actor establishing persistence with reverse_ssh, an outbound connection that survives an update and slips past controls built to block inbound access, alongside fake VMware cron jobs, a web shell and a systemd service. An organisation that patches a vCenter that was already compromised in August has closed the front door on someone who is still inside.
The commercial exposure for UK organisations
Regulatory. Root on the control plane is presumptive access to everything the virtual estate holds, which puts the 72-hour clock under UK GDPR Article 33 within reach the moment compromise is suspected, not confirmed. Financial entities operating in the EU carry DORA's incident classification and reporting duties; essential and important entities under NIS2 face a 24-hour early warning. Two of the five most affected countries in this campaign, Germany and France, sit inside that EU regime, so UK groups with European operations should assume the question will be asked on both sides of the Channel. Separately, the Cyber Resilience Act's Article 14 reporting obligation for actively exploited vulnerabilities applied from 11 September, which will raise the volume and speed of vendor disclosures reaching UK buyers. More information will arrive faster. The duty to act on it has not moved.
Financial. Broadcom's remediation is an update, but the recovery from a suspected compromise is not. The documented path is to preserve forensics, rebuild the appliance from a known-good baseline, rotate the machine account, directory and single sign-on credentials, TLS material and every ESXi host account, then keep monitoring outside the device. Where ransomware has reached the datastores, add the cost of restoring virtual machines whose high-availability agent was deliberately removed. That is an incident response retainer drawn down, days of specialist time, and a rotation exercise touching the identity domain. Cyber insurers increasingly condition cover on documented patch timelines for catalogued vulnerabilities; a vCenter still unpatched in October, weeks after a federal deadline, is a difficult claim.
Contractual. For much of the UK mid-market the virtualisation platform is installed and nominally maintained by a managed service provider or a systems integrator. The questions are whether the contract names control-plane patching as the provider's obligation, on what timeline, with what evidence, and who is told within hours when a vendor publishes a catalogued critical. A seven-week gap between patch and ransomware is long enough that a silent contract has already been tested, and the customer may not know the result.
Governance. Boards ask about endpoints and servers. Few ask how many management consoles the organisation runs, whether any are reachable from the internet, and who owns each one. vCenter, by design, sits above and outside the endpoint tooling the SOC relies on, which is precisely why the observed actor could operate on it for days and then encrypt the ESXi logs to erase the record. Restricting the console to an internal management network reduces the exposure but does not remove it: an attacker who has already reached the internal network, which is the usual precondition for ransomware, reaches the management plane the same way.
What leaders should do now
- Find every vCenter and give each one a named owner by close of business. On premises, hosted, or run by a provider; which build; and whether the management interface is reachable from the internet. If nobody can produce that inventory within a working day, that gap is itself the finding.
- Confirm the patch, then assume nothing. The fix is from July. Any vCenter that went unpatched into August should be treated as compromised until evidenced otherwise, because exploitation was widespread in that window and the actor worked to hide it. Confirming the current build is necessary but not sufficient.
- Hunt for persistence, not just patch level. Look for reverse_ssh and unexpected outbound connections from the appliance, new administrator accounts in the identity domain, altered or impersonated cron jobs, and web shells. A patched box can still hold an intruder who arrived before the update.
- Rebuild and rotate where there is any doubt. A fresh appliance from a known-good baseline, and rotation of the machine account, directory and single sign-on credentials, TLS material and ESXi host accounts. A patched console with unrotated keys and a live backdoor is not remediated.
- Put the control plane on the risk register with a patch clock. A standing policy of a maximum interval, measured in days not weeks, from vendor disclosure to patch or isolation for internet-facing management systems, an exception register the executive can see, and a named approver. On the evidence of this campaign, the next such advisory is a matter of when.
Three questions for the board
- How many virtualisation management consoles does this company run, are any reachable from the internet, and who owns each one by name?
- If a vCenter had been rooted in the first week of August, before we patched, what could the attacker reach, which credentials would they now hold, and have we hunted for them rather than assuming the patch closed it?
- What does our managed service or integrator contract say happens in the first 72 hours after a vendor publishes an exploited critical on our virtualisation platform, and when did we last test that it happens?
The strategic takeaway
Virtualisation consolidated the estate onto a handful of consoles, and that consolidation was the point: fewer things to run, fewer things to manage. This campaign is the bill for it. The console that manages everything is the asset worth compromising, and the interval between a patch being available and a patch being applied is now the entire risk, owned entirely by the organisation that owns the box. The difference between a controlled patch cycle and a ransomware call is not a product. It is whether a named person is accountable for the machine that runs the estate, holds it to a patch clock measured in days, and hunts on the assumption that a missed week may already have cost them. Meeting a deadline on paper is not the same as closing the risk, and attackers have learned to work the gap between the two.
Confidence note
Confirmed. The existence, severity and mechanics of CVE-2026-59310 and CVE-2026-59309; that both are unauthenticated, remotely exploitable and score CVSS 9.8; that there is no workaround; the fixed builds; and Broadcom's classification of the change as an emergency. All from Broadcom advisory VMSA-2026-0006 and its questions-and-answers supplement, 29 July 2026. That exploitation of CVE-2026-59310 began on 3 August, five days after disclosure, that 361 victim IP addresses across 47 countries were identified with the geographic split cited, and the attack chain from syslog path traversal through reverse_ssh persistence, domain administrator account creation, the pivot to ESXi and Babuk-derived ransomware, are from QUIRSO's published incident analysis. The CISA KEV listing on 18 August, the 21 August federal deadline under BOD 26-04, and the weekend update flagging ransomware use are from CISA and BleepingComputer, 15 September 2026. The figure of more than 450 exposed vCenter servers is Shadowserver's, reported by BleepingComputer. The two-clocks framing is Jason Soroko of Sectigo, quoted by Infosecurity Magazine.
Assessed. The attribution of the campaign to a Chinese-speaking, China-nexus actor is QUIRSO's assessment at moderate confidence, based on language artifacts, tooling and working hours, and QUIRSO tracks it as an uncategorised intrusion set rather than a named group. QUIRSO also assesses that the ransomware may not have been the primary objective and could be a smokescreen, since its detailed ransomware analysis covered only one of the compromised systems and it cannot confirm ransomware was deployed across all 361. That MSP-managed virtualisation is widespread in the UK mid-market is our commercial observation, not a measured figure.
Not known. Which ransomware operators CISA is now tracking on this flaw, how many organisations have been encrypted, whether any confirmed UK victim exists, and how many of the 450-plus exposed servers remain unpatched. CISA has not published the ransomware detail and no complete victim accounting is public at the time of writing.
Who in your company owns the console that runs the estate?
Garzon Cyber Solutions is built to put questions like this on the risk register with a named owner, map the controls to what regulators, customers and insurers actually ask for, and place the people who keep the answer current. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Broadcom, VMware Security Advisory VMSA-2026-0006, 29 July 2026 · Broadcom, VMSA-2026-0006 Questions and Answers · BleepingComputer, "CISA: Critical VMware RCE flaw now exploited by ransomware gangs", Sergiu Gatlan, 15 September 2026 · CISA, Known Exploited Vulnerabilities catalogue, CVE-2026-59310 · QUIRSO GmbH, "Global Exploitation of CVE-2026-59310 by Suspected Chinese-Nexus APT", August 2026 · The Hacker News, "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware", 17 August 2026 · Rapid7, "Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution", 30 July 2026 · Infosecurity Magazine, "vCenter Flaw Exploited Just Five Days After Disclosure", Alessandro Mascellino, 13 August 2026 · The Shadowserver Foundation, VMware vCenter CVE-2026-59310 Exploitation Victim Special Report
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification and specialist technology recruitment as one integrated capability for organisations in the UK, EU and Americas. We are a young firm and we publish our own research. Founder Jonathan Garzon spent his career selling cybersecurity, compliance and technology to security and technology buyers, working alongside marketing and technical colleagues, before building GCS around a single argument: delivered in the right order, security, compliance and the people to sustain them stop being three cost lines and become one commercial capability.