CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4514

As cited

Copy frozen at (site build).

ransomware

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Researchers have attributed exploitation of CVE-2026-59310, a critical directory-traversal flaw in VMware vCenter (CVSS 9.8), to a suspected China-linked APT group. The attackers are deploying a Babuk-derived ransomware variant against affected organizations.

Why it matters: VMware vCenter administrators and organizations running vulnerable instances face immediate risk of code execution and ransomware deployment; patching CVE-2026-59310 is a priority given active exploitation by a sophisticated threat actor.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Researchers have attributed exploitation of CVE-2026-59310, a critical directory-traversal flaw in VMware vCenter (CVSS 9.8), to a suspected China-linked APT group. The attackers are deploying a Babuk-derived ransomware variant against affected organizations.

Why it matters: VMware vCenter administrators and organizations running vulnerable instances face immediate risk of code execution and ransomware deployment; patching CVE-2026-59310 is a priority given active exploitation by a sophisticated threat actor.

VendorsVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary