VMware vCenter Flaw Exploited for Babuk Ransomware Attacks

China-linked actor exploits critical VMware vCenter flaw to deploy Babuk-based ransomware

The exploitation of a VMware vCenter vulnerability, CVE-2026-59310, by a suspected China-nexus group has triggered urgent warnings across the cybersecurity community. This VMware vCenter flaw is currently being used to deliver Babuk-derived ransomware, affecting organisations running vulnerable vCenter versions. Immediate action is recommended to prevent impact from this ongoing attack.

Critical Details of the VMware vCenter Flaw

On 4 August 2026, security researchers reported active exploitation of CVE-2026-59310, a directory traversal vulnerability in VMware vCenter. The flaw carries a CVSS score of 9.8, highlighting its severity. It allows unauthenticated attackers to execute arbitrary code on affected systems by manipulating file paths, giving them significant control over the target server.

This vulnerability primarily affects VMware vCenter Server products prior to the latest Broadcom patch release. Attackers are leveraging this flaw to gain initial access, bypassing authentication measures and directly interacting with the underlying operating system.

  • CVE: 2026-59310
  • Attack Vector: Directory traversal via crafted requests
  • Affected Products: VMware vCenter Server (unpatched versions)
  • Severity: 9.8 (Critical)
  • Patch Available: Yes, via Broadcom

According to incident analysis, the flaw can be exploited remotely and requires no prior authentication, making internet-exposed vCenter servers especially vulnerable.

Attack Timeline and Methodology

The first signs of exploitation emerged within days of the public disclosure of CVE-2026-59310. Security monitoring detected a surge in suspicious activity targeting vCenter servers from 2 August 2026 onwards. The threat actor, believed to be linked to a China-nexus APT, quickly integrated the exploit into its toolkit.

Exploitation Process

The attack unfolds in several stages:

  • The attacker scans for publicly accessible vCenter servers running unpatched software.
  • Using a specially crafted HTTP request, the adversary manipulates directory paths, triggering the vulnerability.
  • Arbitrary code is executed on the compromised server, establishing remote access.
  • Once inside, the attacker deploys ransomware derived from the Babuk codebase, encrypting files and disrupting operations.

The Babuk-derived ransomware used in these attacks is notable for its customisation and targeted approach. Once deployed, it rapidly encrypts data, leaving ransom notes and demanding cryptocurrency payments for file recovery. The use of Babuk code indicates a reuse of proven ransomware techniques, but tailored to exploit the specific VMware vCenter flaw.

Indicators of Compromise

Security researchers have identified several indicators of compromise (IoCs) associated with these attacks, including:

  • Unusual outbound traffic from vCenter servers
  • Presence of Babuk ransomware files or ransom notes
  • Unexpected user accounts or scheduled tasks
  • Log entries showing directory traversal attempts

Organisations running internet-facing or externally accessible vCenter servers without the latest Broadcom patch are at the highest risk. The attacks are ongoing, with reports of successful intrusions and ransomware deployment in multiple sectors.

Current Exploitation Status and Response

By early August 2026, exploitation had moved from proof-of-concept to widespread, automated attacks. Several security firms have observed scanning and exploitation activity aimed at identifying and compromising unpatched VMware vCenter instances globally. The Babuk-derived ransomware campaign is not opportunistic but appears to be coordinated, targeting critical infrastructure and large enterprises.

Broadcom has released patches to address CVE-2026-59310. However, threat intelligence shows that many organisations have yet to apply the updates, leaving significant numbers of vCenter servers exposed. Attackers continue to prioritise these vulnerable systems, using automated tools to rapidly deploy ransomware once access is gained.

Potential Impact

The impact of successful exploitation is severe. Compromised systems may experience:

  • Widespread data encryption and loss of access to virtual machines
  • Operational downtime and business disruption
  • Potential data exfiltration or further lateral movement within the network
  • Financial losses related to ransom payments and recovery costs

Organisations in critical sectors such as healthcare, finance and manufacturing are particularly exposed due to their reliance on virtualised environments managed by vCenter.

Why This Attack Matters

This campaign demonstrates how quickly threat actors can weaponise newly disclosed vulnerabilities, especially those affecting widely used enterprise software like VMware vCenter. The combination of a critical, remotely exploitable flaw and effective ransomware techniques raises the stakes for organisations relying on virtualisation platforms.

The involvement of a suspected China-nexus APT group further highlights the increasing sophistication and speed of threat actor response to security disclosures.

Recommended Actions for Organisations

  • Immediately apply Broadcom’s patch for CVE-2026-59310 to all affected VMware vCenter servers.
  • Audit external exposure: restrict or monitor remote access to vCenter servers.
  • Hunt for indicators of compromise, focusing on the presence of Babuk ransomware artefacts.
  • Test and validate backup procedures to ensure rapid recovery if impacted.

Timely action is essential to prevent business disruption and data loss.

Originally reported by thehackernews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call