VMware vCenter Zero-Day: CVE-2026-59310 Hits 47 Nations

VMware vCenter Zero-Day: CVE-2026-59310 Hits 47 Nations

A single flaw in VMware vCenter has turned into one of the more consequential enterprise-security stories of August 2026. Tracked as CVE-2026-59310, the directory-traversal bug carries a CVSS score of 9.8 out of 10 and is now confirmed as actively exploited across data centers in 47 countries, according to threat intelligence gathered by Check Point Research and The Hacker News. Attackers are using it to drop reverse SSH binaries on compromised vCenter servers, then pivoting to deploy Babuk-derived ransomware. The campaign lands in the same week Microsoft shipped fixes for 421 CVEs on its August Patch Tuesday, including a Windows zero-day already weaponized by North Korea’s Lazarus Group. Together, these disclosures paint a picture of an unusually aggressive exploitation window for enterprise infrastructure this month.