Suspected China-Linked Hackers Exploit Critical VMware vCenter Flaw to Deploy Ransomware
Security researchers have linked a suspected China-nexus advanced persistent threat (APT) group to active exploitation of a newly patched, severe vulnerability in Broadcom's VMware vCenter server. Tracked as CVE-2026-59310, the flaw carries a near-maximum severity score of 9.8 out of 10 and is a directory-traversal issue that allows attackers to execute arbitrary code on affected systems.
Once exploited, the attackers have been observed deploying ransomware derived from the leaked Babuk source code, a toolkit that has been reused by multiple criminal and state-linked groups since its public release. Because vCenter is a core management tool for many virtualised business environments, successful exploitation can give attackers broad access to an organisation's virtual infrastructure, potentially affecting many servers and systems at once.
The combination of a critical unpatched vulnerability and ransomware deployment makes this a high-priority threat for any organisation running VMware vCenter, particularly given the severity score and the real-world exploitation already observed. Businesses using virtualised infrastructure should treat this as an urgent patching priority.