Technology newsroom
Urgent Warning! Chinese Hackers Exploit Critical VMware vCenter Vulnerability (CVE-2026-59310), Deploy Babuk Ransomware
A critical security vulnerability (CVSS 9.8) has been found in VMware vCenter Server, exploited by a hacker group believed to be linked to China to install Babuk ransomware. System administrators are advised to update patches immediately.
π Key Takeaways:
- A critical vulnerability (CVSS 9.8), CVE-2026-59310, has been found in VMware vCenter Server, allowing attackers to execute code remotely.
- An APT group, suspected to be linked to China, is actively exploiting this vulnerability to attack organizations.
- The objective is to install a new ransomware variant, developed from Babuk, to encrypt data and demand ransom.
Cybersecurity researchers have issued an urgent warning about active exploitation of a recently patched security vulnerability in Broadcom's VMware vCenter Server product, identifying the attackers as an Advanced Persistent Threat (APT) group suspected of having ties to China.
The attack leverages vulnerability CVE-2026-59310, rated as Critical with a CVSS score of 9.8. This vulnerability is an extremely dangerous Directory Traversal type, allowing attackers to execute arbitrary malicious code on the server remotely without authentication. This poses a nightmare scenario for all IT infrastructure administrators.
βοΈ Attack Pattern and Impact
The hacker group exploits this vulnerability to breach the target organization's network. After gaining control of the vCenter Server, the next step is to install a new ransomware variant, developed from the source code of Babuk Ransomware, which caused severe damage in the past. Once active, the ransomware encrypts all critical files within the virtualization system, leading to business disruption and substantial ransom demands.
π‘οΈ Urgent Recommendations and Prevention
Broadcom and VMware have already released security patches to address CVE-2026-59310. All System Administrators are strongly advised to update the security patches on their VMware vCenter Servers as soon as possible, as active attacks are currently ongoing. Leaving systems vulnerable is akin to opening the door for cybercriminals to cause damage to your organization at any time.
π¬ Does your organization use VMware vCenter? Have you checked and updated to the latest security patches? Share your status in the comments!