PGH Networks

Ransomware Gangs Are Now Exploiting Critical VMware vCenter Flaw

September 15, 2026· PGH Networks Team· 5 min readCybersecurity
Ransomware Gangs Are Now Exploiting Critical VMware vCenter Flaw

What happened

The U.S. Cybersecurity and Infrastructure Security Agency has warned security teams that ransomware groups have joined the ongoing attacks against a critical remote code execution vulnerability in VMware vCenter, according to reporting from BleepingComputer. The flaw was patched in July, but unpatched servers are still being found and hit.

That progression is the part worth paying attention to. Exploitation of vCenter bugs usually starts with quieter actors doing reconnaissance and access brokering; once ransomware affiliates pick up a working exploit, the window between "scanned" and "encrypted" collapses to days or hours. If you run vCenter on-premises and you cannot confirm exactly which build you are on, treat that as an open question you need answered today, not a maintenance-window item. We are not going to restate CVE numbers or affected build lists from memory here, verify them against VMware's own advisory for your specific version.

people sitting on chair in front of computer

Why this matters for Pittsburgh-area SMBs

A lot of people assume vCenter is enterprise-only gear. It is not. Across our client base in the region, a 40-person CPA firm running its practice management and document stack on two or three ESXi hosts is completely normal. So is a manufacturer in Butler or Washington County with an ERP server, a historian, and a couple of engineering VMs consolidated onto a single cluster in a closet that also holds the phone system. Law firms with document management and a decade of matter files, specialty medical practices with an on-prem EHR or imaging server, defense suppliers with a segmented CUI enclave that still needs a hypervisor underneath it — same picture.

The reason a vCenter compromise is worse than a compromised file server is leverage. vCenter is the management plane. From there an attacker does not need to move laterally into each guest OS or evade endpoint protection on every VM. They can encrypt the datastores, delete snapshots, and take out the on-prem backup appliance if it lives on the same cluster. Your EDR tooling inside the guests never gets a vote. That is exactly why ransomware crews like hypervisor management targets, and why "we have good endpoint protection" is not a sufficient answer.

There is also the compliance tail. A ransomware event on a hypervisor holding ePHI is a presumptive breach under HIPAA unless your risk assessment says otherwise, with a 60-day notification clock. Under the FTC Safeguards Rule, financial services firms and many accounting practices owe notification to the FTC for qualifying events affecting 500 or more consumers within 30 days. If you are pursuing or holding CMMC Level 2, unpatched, internet-adjacent management infrastructure is a straightforward finding against your flaw-remediation and vulnerability-scanning practices, and DFARS 7012 incident reporting to DoD runs on a 72-hour clock. None of those clocks care that patching was on next quarter's roadmap.

What to do about it this week

  1. Inventory your hypervisor management plane. Confirm whether you run vCenter Server at all, how many instances, and the exact build number of each. If nobody on your team can produce that in ten minutes, that gap is the real finding.
  2. Compare against VMware's advisory and patch. Apply the vendor-supplied fixed build for your version. Where a patch cannot be applied immediately, check VMware's advisory for an approved workaround rather than improvising one — and record the business reason for the delay.
  3. Get vCenter and ESXi off the internet and off the flat LAN. Management interfaces should be reachable only from a jump host or an administrative VLAN behind MFA. Verify this from an outside scan; do not assume the firewall rule you wrote in 2023 still says what you think it says.
  4. Prove your backups survive a hypervisor loss. You need at least one immutable or air-gapped copy that is not stored on the cluster it protects and not deletable with vCenter credentials. Then do a real restore test of one production VM and time it.
  5. Rotate and segment hypervisor credentials. Separate admin accounts from daily-driver accounts, enforce MFA on identity sources, and pull any shared root passwords out of spreadsheets and into a vault. Assume prior exposure if the host was unpatched and internet-reachable.
  6. Hunt, do not just patch. Patching closes the door; it does not evict anyone already inside. Review vCenter and ESXi logs for unexpected SSH or shell enablement, new local accounts, unfamiliar VM deployments, and out-of-hours logins. Escalate to your MDR provider if anything looks off.
  7. Write down the decision. Note what you patched, when, what you deferred, and why. That short record is what turns a scramble into evidence for your SOC 2, HIPAA, or CMMC file — and it is the sort of thing your vCIO should be maintaining as part of the roadmap, not reconstructing after an incident.

If steps 1 through 4 raise more questions than answers, that is your signal that hypervisor patching needs to be an owned, scheduled process under patch management with monthly reporting, rather than something that happens when someone remembers.

One more thing worth raising at your next review: if you have been consolidating on-prem workloads to shrink your attack surface, this is a reasonable moment to revisit which of those VMs genuinely need to stay in the closet versus moving to Microsoft 365 and Azure. Fewer hypervisors is fewer emergency Tuesdays.

Talk it through with us

We handle hypervisor and firmware patching, network segmentation reviews, immutable backup design, and 24/7 monitoring for small and mid-sized organizations across Pittsburgh and Western PA, with the documentation your auditors and prime contractors expect. If you are not certain whether your vCenter is patched, call us at 724.888.7007 or reach out through the contact form and we will help you confirm it.

Share

Related reading

Call usBook a meeting