Ransomware operators are exploiting CVE-2026-59310, a critical unauthenticated VMware vCenter Server flaw in the Syslog server, to compromise vCenter management infrastructure and encrypt managed ESXi virtual machines with Babuk-derived payloads. Broadcom patched the vulnerability on July 29, but successful exploitation was observed within five days; reported activity affected 361 victim IP addresses across 47 countries. No ransomware group has been publicly identified.
Initial intrusions used reverse-SSH tunnels and cron-job persistence, activity assessed as likely associated with an advanced persistent threat actor before ransomware deployment emerged. CISA has added the 9.8-CVSS vulnerability to its Known Exploited Vulnerabilities catalog and warned of ransomware use. Organizations should urgently install VMware's latest cumulative updates, remove vCenter interfaces from direct internet exposure, limit administration to trusted networks and jump hosts, and investigate formerly exposed or unpatched vCenter instances for persistence and unauthorized access.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CISA warned that ransomware groups were exploiting CVE-2026-59310 against VMware vCenter. Reporting indicated that operators used compromised vCenter instances to deploy Babuk-derived ransomware payloads that encrypt managed ESXi virtual machines; no specific ransomware group was publicly named.
CISA added CVE-2026-59310 to its Known Exploited Vulnerabilities catalog and required U.S. federal civilian agencies to remediate it by August 21. CISA also designated the issue for forensic triage, signaling that affected organizations should investigate for compromise as well as patch.
By August 5, QUIRSO had observed approximately 343 of 361 unique victim IP addresses associated with the CVE-2026-59310 campaign. The addresses spanned 47 countries, though the researchers cautioned that IP addresses did not necessarily represent distinct victim organizations.
QUIRSO observed the first successful compromises linked to CVE-2026-59310 five days after patches became available. The campaign was assessed as likely tied to an advanced persistent threat actor and used malicious cron jobs and reverse_ssh tunnels for persistence and outbound access.
Broadcom disclosed and released patches for CVE-2026-59310 in advisory VMSA-2026-0006. The unauthenticated CVSS 9.8 directory-traversal flaw in vCenter's Syslog server could allow network-accessible attackers to execute arbitrary code; the advisory also addressed CVE-2026-59309.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cybercenter.space
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.