VMware CVE-2026-59310 Added to CISA KEV Under Active Exploitation
VMware has had one actively-exploited vulnerability added to CISA's Known Exploited Vulnerabilities Catalog, underscoring the immediate threat posed by this flaw.

Key findings
- CVE-2026-59310, a VMware vulnerability, was added to CISA's KEV catalog on August 18, 2026.
- The flaw is confirmed to be under active exploitation by threat actors.
- Immediate patching and mitigation are critical to protect against ongoing attacks.
- Federal agencies must remediate this vulnerability by February 14, 2027.
CISA officially added CVE-2026-59310, a critical VMware vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog on August 18, 2026. This inclusion confirms that the flaw is under active exploitation by threat actors in real-world attacks, necessitating immediate attention from all organizations utilizing affected VMware products.
The vulnerability, identified as CVE-2026-59310, represents a significant security risk. While specific technical details regarding the nature of the flaw and its exploitation methods are not yet widely publicized, its presence in the KEV catalog serves as a definitive warning that adversaries are actively leveraging it to compromise systems. This makes it a high-priority target for remediation.
At present, there is no public information linking CVE-2026-59310 directly to ransomware campaigns. However, any actively exploited vulnerability can serve as a critical initial access vector, potentially leading to a wide range of malicious activities, including data theft, system disruption, and the eventual deployment of ransomware or other destructive payloads.
Organizations must prioritize the immediate patching and mitigation of CVE-2026-59310. CISA's directive for federal civilian executive branch agencies mandates remediation of KEV catalog vulnerabilities within a specific timeframe, typically six months from the add date. For this vulnerability, the due date for federal agencies is February 14, 2027. All other organizations are strongly advised to follow this guidance and apply available security updates or implement recommended mitigations without delay to protect their environments from ongoing threats.