CISA: Critical VMware RCE flaw now exploited by ransomware gangs

2026-09-15T13:23:23Z•36f839323fa17bff6a7083762e849c82b5471928ed31c9d9392f92093ddea078
AWSAzureCisco Secure Email GatewayClickFixMicrosoft updatesOAuth token theftVMware vCenteractive exploitationcloud credential theftcommand execution as rootcredential theftcybercrimedata breachexposed development serversincident responseinformation-stealing malwareransomwareremote code executionzero-day

What happened

A BleepingComputer security-news feed covering active exploitation of a critical VMware vCenter RCE vulnerability by ransomware groups, a Cisco Secure Email Gateway zero-day exploited to execute commands as root, breaches and credential/token theft, exposed development servers targeting AWS and Azure secrets, and other cybercrime and software-update incidents. The most urgent items involve vulnerabilities under active exploitation and attacks affecting exposed enterprise infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
36f839323fa17bff6a7083762e849c82b5471928ed31c9d9392f92093ddea078
Enrichment time
2026-09-15T13:23:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.