decrypted · 16 september 2026 · vulnerabilities and patching · supply chain · surveillance and privacy
Ransomware gangs catch up with a VMware bug CISA flagged in August
A critical VMware vCenter flaw that Broadcom patched on 29 July has followed the pattern every security team dreads: exploited within days by suspected state-linked attackers, added to America's list of known exploited vulnerabilities on 18 August, and now, CISA said this week, picked up by ransomware crews too. CVE-2026-59310 lives in vCenter's Syslog server, the management console behind a huge slice of enterprise and public sector virtualisation, and it needs no login at all.
A management console that trusts what it's told
vCenter's Syslog service accepts log messages from other systems and writes them to disk under a filename it is given. CVE-2026-59310 is a path traversal bug: send it a filename laced with dot-dot-slash instructions instead of a normal one, and the server writes the resulting file wherever that path points, including places it should never reach. It is the digital equivalent of a courier that takes whatever address is on the label, even when the label reads "the manager's safe, third drawer down", and posts the parcel through anyway. No credentials, no user interaction, and a CVSS score of 9.8 to show for it.
Five weeks from patch to ransomware
Researchers tracking the campaign found compromised vCenter servers phoning home within days of the July patch, and by early August there were 361 confirmed victim IP addresses across 47 countries. CISA's own catalogue entry for CVE-2026-59310 now carries the note "ransomware known to be used", meaning criminal crews have started riding the same hole that state-linked intruders opened first. BleepingComputer reported this week that Shadowserver was still tracking more than 450 vCenter instances reachable from the open internet.
The Secure by Design lesson here is not subtle: a service that parses attacker-controlled filenames to decide where it writes data should never be reachable without authentication, full stop. That the Syslog server was built to trust its input is the root cause; the espionage, the ransomware and the five-week countdown are all downstream of that one decision. For UK organisations running vSphere, which is most of them somewhere in the estate, the practical point is blunter still: a patch released in July and still unapplied in September is not a backlog item. It is an open door with someone else's name already on the mat.
Also this week
JFrog Artifactory instances are being backdoored, not just breached. Researchers at Wiz found attackers chaining two authentication flaws, CVE-2026-42018 and CVE-2026-42016, to turn an anonymous request into an admin-scoped token, then dropping Rust-based backdoors and malicious Groovy plugins for persistence. Artifactory holds the software packages that feed into an organisation's builds, so a compromised instance is not just a breach, it is a foothold in the supply chain of everything that instance serves. CISA added both CVEs to its exploited list on 11 September; if a build pipeline touches a self-hosted Artifactory, patching it belongs above routine IT hygiene, not alongside it.
Apple's fight over a secret UK order to break iCloud encryption is back before the tribunal. The Investigatory Powers Tribunal is due to hear Apple's latest complaint against a Home Office notice demanding backdoor access to encrypted iCloud data for UK users, an order Apple answered by withdrawing Advanced Data Protection from the UK market rather than comply. Two US senators, one from each party, wrote to the tribunal this month asking it to lift the secrecy around the case, arguing that weakening encryption creates vulnerabilities hostile states can exploit too. Whatever the tribunal decides, the engineering point holds for any UK organisation weighing its own vendor access requests: a backdoor built for one authorised party is a vulnerability available to whoever else finds it. "Trust us with the key" is not a control.
Sources
- CISA: Critical VMware vCenter RCE flaw now exploited by ransomware gangs
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-59310
- Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
- Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
- US lawmakers call for UK court to lift secrecy over Apple 'backdoor' surveillance
- Privacy International and Liberty complaint against Government's 'backdoor' access to Apple data to be heard by Tribunal
If your organisation needs help thinking through Secure by Design in practice, get in touch.
More like this
- The bill comes due for the SSO flaw that hit 138 companies 13 september 2026
- The Check Point VPN flaws that haven't been exploited yet 14 september 2026
- Microsoft's Windows Defender patch didn't survive the week 14 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.