A single directory traversal bug in VMware vCenter Server has turned into one of the broadest hypervisor-level ransomware campaigns of 2026. Security researchers tracking exploitation of CVE-2026-59310, a CVSS 9.8 flaw in vCenter’s Syslog server, say a suspected China-nexus actor has already compromised 361 victim IP addresses spread across 47 countries, using the access to drop Babuk-derived ransomware directly onto ESXi hosts. The campaign, first flagged in threat intelligence reporting during the week of August 17-23, 2026, has pushed the bug onto the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog alongside eight other actively exploited flaws added the same week.
VMware vCenter CVE-2026-59310: Babuk Hits 47 Nations



