What happened
German incident response firm QUIRSO attributed a global exploitation campaign against CVE-2026-59310, a critical directory traversal flaw in Broadcom's VMware vCenter Server rated 9.8 out of 10, to a suspected Chinese-speaking threat actor, with moderate confidence based on language artifacts in attack scripts, tooling choices, and working hours consistent with the UTC+8 time zone. Broadcom released a fix on July 29. The researchers counted roughly 361 compromised IP addresses across 47 countries, with the United States among the most heavily targeted. Exploitation gives the attacker code execution as root on the vCenter appliance, after which the group deployed a backdoor and a reverse SSH tool, and in some cases ransomware derived from the leaked Babuk code. Analysts noted the ransomware may serve partly as a smokescreen, complicating forensic investigation of the espionage activity underneath.
Why it matters for your business
vCenter is the management console for VMware server environments, which makes it the skeleton key to every virtual machine it controls. Plenty of small and mid-sized companies run VMware without knowing it, because it sits underneath the server their IT provider or data center hosts for them. A three-week-old patch with active nation-state exploitation is exactly the situation where you want to verify rather than assume. For the DC area's federal contractors, an APT campaign hitting US infrastructure through management software is also a preview of the questions primes and agencies will ask their suppliers.
What to do about it
- If you run VMware in-house, confirm vCenter is patched for CVE-2026-59310 and that the management interface is not reachable from the internet
- If your servers are hosted or managed by a third party, ask them in writing whether their VMware environment is patched for this flaw
- Treat virtualization management consoles like crown jewels: restrict access, log activity, and include them in incident response plans
