Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Broadcom fixed one critical VMware flaw seven weeks before ransomware arrived.

Sergiu Gatlan reported the exploitation for BleepingComputer on 15 September.

ERP LEADERS news desk · · First reported by BleepingComputer · Edition no. 9

CVE-2026-59310 is a critical directory traversal in the vCenter Syslog server that unauthenticated attackers can use to run code.

Broadcom released the fix on 29 July and told customers to treat it as "an emergency" and to "install patches as soon as possible".

CISA added the flaw to its Known Exploited Vulnerabilities catalog on 18 August, giving federal agencies three days to patch. Over the weekend, the agency updated the entry to flag active exploitation by ransomware gangs.

Forensics firm QUIRSO identified more than 361 compromised IP addresses across 47 countries before the ransomware activity appeared. It also reported that a suspected state actor had left behind a reverse SSH tool for persistence.

Shadowserver counts more than 450 vCenter servers exposed online.

CISA has now tagged 26 VMware vulnerabilities as exploited in five years. Nine were used by ransomware operations, according to the agency. Control of vCenter can give an attacker an administrative path to the virtual machines it manages.

Seven weeks after a vendor calls a patch an emergency, what is still unpatched in your estate?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on Broadcom

  1. 17 SeptFiled later

    Broadcom raised VMware prices by 10x or more, European cloud providers say.

  2. 10 Sept

    VMware pulled the toolkit rivals used to move customers off it. Without notice.

All 3 Broadcom stories

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01