The exploitation of a VMware vCenter vulnerability, CVE-2026-59310, by a suspected China-nexus group has triggered urgent warnings across the cybersecurity community. This VMware vCenter flaw is currently being used to deliver Babuk-derived ransomware, affecting organisations running vulnerable vCenter versions. Immediate action is recommended to prevent impact from this ongoing attack.
Critical Details of the VMware vCenter Flaw
On 4 August 2026, security researchers reported active exploitation of CVE-2026-59310, a directory traversal vulnerability in VMware vCenter. The flaw carries a CVSS score of 9.8, highlighting its severity. It allows unauthenticated attackers to execute arbitrary code on affected systems by manipulating file paths, giving them significant control over the target server.
This vulnerability primarily affects VMware vCenter Server products prior to the latest Broadcom patch release. Attackers are leveraging this flaw to gain initial access, bypassing authentication measures and directly interacting with the underlying operating system.
- CVE: 2026-59310
- Attack Vector: Directory traversal via crafted requests
- Affected Products: VMware vCenter Server (unpatched versions)
- Severity: 9.8 (Critical)
- Patch Available: Yes, via Broadcom
According to incident analysis, the flaw can be exploited remotely and requires no prior authentication, making internet-exposed vCenter servers especially vulnerable.
Attack Timeline and Methodology
The first signs of exploitation emerged within days of the public disclosure of CVE-2026-59310. Security monitoring detected a surge in suspicious activity targeting vCenter servers from 2 August 2026 onwards. The threat actor, believed to be linked to a China-nexus APT, quickly integrated the exploit into its toolkit.
Exploitation Process
The attack unfolds in several stages:
- The attacker scans for publicly accessible vCenter servers running unpatched software.
- Using a specially crafted HTTP request, the adversary manipulates directory paths, triggering the vulnerability.
- Arbitrary code is executed on the compromised server, establishing remote access.
- Once inside, the attacker deploys ransomware derived from the Babuk codebase, encrypting files and disrupting operations.
The Babuk-derived ransomware used in these attacks is notable for its customisation and targeted approach. Once deployed, it rapidly encrypts data, leaving ransom notes and demanding cryptocurrency payments for file recovery. The use of Babuk code indicates a reuse of proven ransomware techniques, but tailored to exploit the specific VMware vCenter flaw.
Indicators of Compromise
Security researchers have identified several indicators of compromise (IoCs) associated with these attacks, including:
- Unusual outbound traffic from vCenter servers
- Presence of Babuk ransomware files or ransom notes
- Unexpected user accounts or scheduled tasks
- Log entries showing directory traversal attempts
Organisations running internet-facing or externally accessible vCenter servers without the latest Broadcom patch are at the highest risk. The attacks are ongoing, with reports of successful intrusions and ransomware deployment in multiple sectors.
Current Exploitation Status and Response
By early August 2026, exploitation had moved from proof-of-concept to widespread, automated attacks. Several security firms have observed scanning and exploitation activity aimed at identifying and compromising unpatched VMware vCenter instances globally. The Babuk-derived ransomware campaign is not opportunistic but appears to be coordinated, targeting critical infrastructure and large enterprises.
Broadcom has released patches to address CVE-2026-59310. However, threat intelligence shows that many organisations have yet to apply the updates, leaving significant numbers of vCenter servers exposed. Attackers continue to prioritise these vulnerable systems, using automated tools to rapidly deploy ransomware once access is gained.
Potential Impact
The impact of successful exploitation is severe. Compromised systems may experience:
- Widespread data encryption and loss of access to virtual machines
- Operational downtime and business disruption
- Potential data exfiltration or further lateral movement within the network
- Financial losses related to ransom payments and recovery costs
Organisations in critical sectors such as healthcare, finance and manufacturing are particularly exposed due to their reliance on virtualised environments managed by vCenter.
Why This Attack Matters
This campaign demonstrates how quickly threat actors can weaponise newly disclosed vulnerabilities, especially those affecting widely used enterprise software like VMware vCenter. The combination of a critical, remotely exploitable flaw and effective ransomware techniques raises the stakes for organisations relying on virtualisation platforms.
The involvement of a suspected China-nexus APT group further highlights the increasing sophistication and speed of threat actor response to security disclosures.
Recommended Actions for Organisations
- Immediately apply Broadcom’s patch for CVE-2026-59310 to all affected VMware vCenter servers.
- Audit external exposure: restrict or monitor remote access to vCenter servers.
- Hunt for indicators of compromise, focusing on the presence of Babuk ransomware artefacts.
- Test and validate backup procedures to ensure rapid recovery if impacted.
Timely action is essential to prevent business disruption and data loss.
Originally reported by thehackernews.com.






