Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

Urgent Warning! Chinese Hackers Exploit Critical VMware vCenter Vulnerability (CVE-2026-59310), Deploy Babuk Ransomware

A critical security vulnerability (CVSS 9.8) has been found in VMware vCenter Server, exploited by a hacker group believed to be linked to China to install Babuk ransomware. System administrators are advised to update patches immediately.

Edited by SyncTech Solution Published Source Original source
Urgent Warning! Chinese Hackers Exploit Critical VMware vCenter Vulnerability (CVE-2026-59310) to Deploy Babuk Ransomware

πŸ“Œ Key Takeaways:
- A critical vulnerability (CVSS 9.8), CVE-2026-59310, has been found in VMware vCenter Server, allowing attackers to execute code remotely.
- An APT group, suspected to be linked to China, is actively exploiting this vulnerability to attack organizations.
- The objective is to install a new ransomware variant, developed from Babuk, to encrypt data and demand ransom.

Cybersecurity researchers have issued an urgent warning about active exploitation of a recently patched security vulnerability in Broadcom's VMware vCenter Server product, identifying the attackers as an Advanced Persistent Threat (APT) group suspected of having ties to China.

The attack leverages vulnerability CVE-2026-59310, rated as Critical with a CVSS score of 9.8. This vulnerability is an extremely dangerous Directory Traversal type, allowing attackers to execute arbitrary malicious code on the server remotely without authentication. This poses a nightmare scenario for all IT infrastructure administrators.

βš™οΈ Attack Pattern and Impact
The hacker group exploits this vulnerability to breach the target organization's network. After gaining control of the vCenter Server, the next step is to install a new ransomware variant, developed from the source code of Babuk Ransomware, which caused severe damage in the past. Once active, the ransomware encrypts all critical files within the virtualization system, leading to business disruption and substantial ransom demands.

πŸ›‘οΈ Urgent Recommendations and Prevention
Broadcom and VMware have already released security patches to address CVE-2026-59310. All System Administrators are strongly advised to update the security patches on their VMware vCenter Servers as soon as possible, as active attacks are currently ongoing. Leaving systems vulnerable is akin to opening the door for cybercriminals to cause damage to your organization at any time.

πŸ’¬ Does your organization use VMware vCenter? Have you checked and updated to the latest security patches? Share your status in the comments!

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.