DEV Community

Cyber Updates 365
Cyber Updates 365

Posted on

Critical VMware vCenter Flaw Exploited by China APT: Patch Now!

Critical VMware vCenter Flaw Exploited by China APT: Patch Now!

Hackers are actively exploiting the VMware vCenter flaw CVE-2026-59310 to deploy Babuk ransomware on ESXi hosts. Read our technical breakdown.

Enterprise virtualization infrastructure remains the primary target for advanced persistent threats seeking total network dominance. A devastating new attack campaign has proven that patching delays of even a few days can lead to catastrophic data center compromise.

The VMware vCenter flaw CVE-2026-59310 is currently being actively exploited by a highly sophisticated, suspected China-nexus threat actor. This critical directory traversal vulnerability allows attackers to execute arbitrary code with root privileges, deploy persistent webshells, and ultimately encrypt ESXi environments with Babuk-derived ransomware.

🔗 Read the Full Technical Breakdown, Explore the C2 WebSockets, and View Mitigation Steps on CyberUpdates365

Top comments (0)