News › security

VMware vCenter Flaw CVE-2026-59310 Exploited, Linked to China-Based APT

By Zayden R., August 17, 2026

A severe vulnerability in VMware vCenter, CVE-2026-59310, is being exploited by a suspected China-based APT group. Engineers need to patch immediately to prevent arbitrary code execution and potential ransomware deployment.

A critical vulnerability in VMware vCenter, identified as CVE-2026-59310 with a CVSS score of 9.8, has come under active exploitation by a suspected China-nexus advanced persistent threat (APT) group. This flaw, a severe directory-traversal vulnerability, allows malicious actors to execute arbitrary code on affected systems. Broadcom released a patch for this flaw on July 29, 2026, but the threat actors began their exploitation campaign just five days later.

The German incident response firm QUIRSO has attributed these attacks to a Chinese-speaking threat actor, likely operating within the UTC+08:00 time zone. This assessment is based on various indicators, including Chinese language artifacts in scripts and tools, as well as activity patterns aligning with typical working hours in Chinese-speaking regions. This campaign has already compromised 361 unique victim IP addresses across 47 countries, with Germany, the U.S., and Turkey bearing the brunt of the attacks.

Notably, one vCenter Server Appliance analyzed by QUIRSO showed signs of being targeted by both CVE-2026-59310 and another vulnerability, CVE-2026-59309, which involves authentication bypass. The attackers used this to create an administrative account and performed vSphere discovery using the REST API, disguised with User-Agent strings like "GoodMoodle-VCFleet/1.0".

For engineers and system administrators, the immediate action is clear: patch your VMware vCenter servers without delay to mitigate this critical risk. The consequences of failing to do so could include unauthorized access and potential deployment of Babuk-derived ransomware, as observed in the current threat landscape.

Sources

Practice this on a real machine

The Linux Camp teaches these topics as hands-on labs on real virtual machines, verified as you type.