Back to News
Cybersecurity

New VMware vCenter Vulnerability Exploited by Suspected APT Linked to China

Researchers warn of a severe VMware vCenter flaw exploited by a China-nexus APT, leading to Babuk-derived ransomware deployment.

Recent investigations have uncovered that a suspected advanced persistent threat (APT) group with links to China is exploiting a critical security vulnerability in VMware vCenter, identified as CVE-2026-59310, which carries a CVSS score of 9.8. This directory-traversal flaw allows attackers to execute arbitrary code, raising significant concerns about the potential for widespread compromise across organizations utilizing this platform. The exploitation of this vulnerability has led to the deployment of Babuk-derived ransomware, highlighting the evolving tactics of cybercriminals in leveraging known flaws for malicious gain.

For businesses, the implications are substantial. Organizations using VMware vCenter must prioritize patching this vulnerability to protect against potential breaches and ransomware attacks. This incident underscores the importance of vigilance in cybersecurity practices, including regular software updates and vulnerability assessments. The ability of APTs to adapt and exploit vulnerabilities reinforces the necessity for a proactive security posture, particularly as cyber threats become increasingly sophisticated. As ransomware attacks continue to rise, understanding and mitigating these risks is crucial for maintaining the integrity and security of business operations.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html)*