Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware
Overview
Cybersecurity researchers have identified a new security threat linked to a suspected China-nexus advanced persistent threat group. The group is exploiting a serious vulnerability in Broadcom's VMware vCenter, known as CVE-2026-59310, which has a CVSS score of 9.8, indicating its severity. This directory-traversal flaw allows attackers to execute arbitrary code on affected systems. Recent reports show that the attackers are deploying Babuk-derived ransomware during these exploits, raising concerns for organizations using VMware vCenter. Companies that rely on this software need to act quickly to secure their environments and protect sensitive data from potential ransomware attacks.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Broadcom VMware vCenter server (affected by CVE-2026-59310)
- Action Required: Organizations should apply the latest security patches provided by VMware for vCenter.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code
Impact
Broadcom VMware vCenter server (affected by CVE-2026-59310)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply the latest security patches provided by VMware for vCenter. It is also advisable to monitor systems for unusual activity and implement additional security measures such as network segmentation and access controls to mitigate the risk of exploitation.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Ransomware, CVE, VMware, and 2 more.