CISA’s KEV catalog now lists CVE-2026-59310 (Broadcom VMware vCenter Path Traversal) with knownRansomwareCampaignUse: Known. BleepingComputer reported the ransomware flag on Sep 15. The flaw is a path traversal that can let a threat actor with network access to vCenter execute arbitrary code. Broadcom’s advisory is in CISA’s notes; the federal remediation due date was already Aug 21 after the Aug 18 KEV add — this update is the ransomware classification, not a new CVE.
Sourced timeline: Broadcom patched on Jul 29, 2026. DFIR shop QUIRSO later reported 361 IP addresses across 47 countries compromised in a suspected APT wave that dropped reverse-SSH persistence (QUIRSO via BleepingComputer); victim orgs: Undisclosed. Shadowserver, per the same writeup, currently tracks over 450 vCenter instances exposed online; patched share Undisclosed. CISA has not published ransomware operator names, encryptor families, or victim counts for this KEV flip; those remain Undisclosed.
Why it matters for the cyber tape: unpatched vCenter is the keys-to-the-estate path into ESXi and guest estates. Treat any internet-reachable or weakly segmented vCenter as emergency patch + forensic triage (CISA forensicTriage: Yes). Primary clock is CISA KEV JSON + Broadcom advisory in the notes; BleepingComputer for the Sep 15 ransomware framing. Patch first; CISA left the ransomware brand blank.
