CVE -2026-59310 , a critical vulnerability in VMware vCenter Server , is at the center of a widespread cyberattack attributed to Chinese hackers . According to The Hacker News , German incident response firm QUIRSO detected the campaign and attributed it with medium confidence to a Chinese-speaking threat actor operating in the UTC+08:00 time zone . The attack began just five days after the vulnerability was publicly disclosed and led to the deployment of ransomware , based on Babuk code , on ESXi infrastructures .

CVE-2026-59310 has a CVSS score of 9.8 and concerns a directory-traversal vulnerability in the VMware vCenter Syslog server . Broadcom released a patch on July 29, 2026 , also addressing a second vulnerability, CVE-2026-59309 , which concerns an authentication bypass. Broadcom clarified that there is no workaround for either vulnerability — the only solution is to immediately apply the available patches. On August 3, 2026 , the company revised its announcement to add express patches for the vCenter 8.0 U2f release .
The CVE-2026-59310 is estimated to have compromised 361 unique IP addresses in 47 countries. The majority of infections were detected in Germany (55), the United States (41), Turkey (38), Iran (26) , and France (25). Notably, no victims were detected in mainland China — a pattern often seen in operations attributed to Chinese state actors. The victims belong to a wide range of sectors: technology, software, cybersecurity, higher education, research, telecommunications, and network services.
See also: Chinese hackers exploit VMware vCenter environments
CVE-2026-59310: Technical analysis of the exploit
The attack chain associated with CVE-2026-59310 starts with the vCenter Server Appliance cron daemon (crond) , which logs a malformed cron file named “zz-poc59310-syslog.log” . This name is indicative: it explicitly refers to the CVE identifier and indicates that this is a proof-of-concept (PoC) exploit that was developed after the technical details of the vulnerability were publicly known. The “-syslog.log” suffix mimics the vCSA remote syslog file naming convention, but the file appears in the /etc/cron.d directory instead of the normal syslog output directory.
In the next step, a curl (or alternatively wget) command is executed to retrieve a backdoor from the address 5.34.177[.]38:9861 and execute it on the system, while the log file is then deleted. The implanted implant, known as “linuxFile”, provides remote command execution capabilities. At the same time, QUIRSO researchers detected the use of an open source reverse-SSH implant for command-and-control (C2) communication, while the attack was completed by encrypting ESXi via ransomware, a derivative of Babuk, with a “.babyk”.
Regarding CVE-2026-59309 , evidence shows malicious activity since August 1, 2026 , with the creation of an administrator account in vCenter from the IP address 146.59.252[.]178 . On August 3 , the attackers performed vSphere discovery via the REST API , using User-Agent strings such as “GoodMoodle-VCFleet/1.0” — an attempt to disguise the activity as legitimate VMware- related traffic , leveraging the name of VCF Fleet , a centralized management tool introduced by Broadcom in VMware Cloud Foundation (VCF) version 9.0 .

CVE-2026-59310 and the attribution to Chinese hackers
The attribution of the exploit campaign to a Chinese-speaking actor is based on multiple pieces of evidence gathered by QUIRSO. Researchers Maike Orlikowski, Çağatay Yürekli , and Denis Szadkowski noted the presence of Chinese language artifacts within scripts created by the attackers, the reuse of research material from a Chinese security publication, and the repeated use of Chinese tools and management software. Additionally, no victims were identified in mainland China, and the activity patterns are consistent with a UTC+08:00.
See also: VMware vCenter Server: Critical vulnerability used in attacks
This profile matches known APT groups linked to China and with a history of exploiting vulnerabilities in virtualization infrastructure. The strategic choice of vCenter as the initial point of entry is particularly concerning: a compromise of a vCenter Server provides essentially complete control over all the virtual machines it manages, allowing for mass outages with minimal effort. This pattern — exploiting virtualization platforms for maximum impact — is a growing trend in modern high-intensity cyberattacks.
It is worth noting that similar campaigns exploiting VMware infrastructure have been observed in the past. The Babuk ransomware, whose source code was leaked in 2021, has been widely used by various groups to create ransomware specifically targeting ESXi environments. The “.babyk” observed in the current campaign confirms this connection.

Protecting against CVE-2026-59310: What to do now
Organizations using VMware vCenter should take immediate action. Broadcom has released patches. Since there is no workaround for CVE-2026-59310, applying patches is the only effective defense.
Beyond immediate patching, QUIRSO experts recommend a number of additional defensive measures. First, removing or severely limiting the exposure of vCenter and vSphere management interfaces to the internet is critical. Second, administrators should check for unexpected ESXi accounts , especially newly created administrative users like the “vcenter_admin” detected in this campaign. Third, detecting cron persistence , reverse-SSH activity , and unusual outbound connections from vCenter or ESXi hosts is essential.
See also: Vulnerabilities in VMware vCenter Server allow code execution
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, organizations should monitor for suspicious file encryption activity, particularly files with the “.babyk”, and segment virtualization management networks. The speed with which CVE-2026-59310 — just five days after public disclosure — underscores the need for immediate response to critical infrastructure vulnerabilities.
