CISA: Critical VMware RCE flaw now exploited by ransomware gangs
2026-09-15T13:23:23Z•36f839323fa17bff6a7083762e849c82b5471928ed31c9d9392f92093ddea078
AWSAzureCisco Secure Email GatewayClickFixMicrosoft updatesOAuth token theftVMware vCenteractive exploitationcloud credential theftcommand execution as rootcredential theftcybercrimedata breachexposed development serversincident responseinformation-stealing malwareransomwareremote code executionzero-day
What happened
A BleepingComputer security-news feed covering active exploitation of a critical VMware vCenter RCE vulnerability by ransomware groups, a Cisco Secure Email Gateway zero-day exploited to execute commands as root, breaches and credential/token theft, exposed development servers targeting AWS and Azure secrets, and other cybercrime and software-update incidents. The most urgent items involve vulnerabilities under active exploitation and attacks affecting exposed enterprise infrastructure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 36f839323fa17bff6a7083762e849c82b5471928ed31c9d9392f92093ddea078
- Enrichment time
- 2026-09-15T13:23:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.