VMware vCenter CVE-2026-59310: China-Linked APT Exploits Critical Flaw, France in the Top 5 Victims
> TL;DR: CVE-2026-59310 (CVSS 9.8) is a path traversal flaw in VMware vCenter that lets an attacker with network access to vCenter execute arbitrary code. CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026. A suspected China-nexus actor has been exploiting it to deploy persistent backdoors and, in at least one case, a Babuk-derived ransomware. France ranks among the most affected countries, with 25 compromised IP addresses out of 361 total across 47 countries.
Why vCenter is such a high-value target
VMware vCenter is the centralized management console for enterprise virtualization infrastructure. Compromising vCenter potentially means compromising every virtual machine it manages — application servers, databases, production environments. It's an extremely high-value pivot point: a single compromised server can grant access to dozens or hundreds of VMs.
The observed attack chain
Geographic breakdown of the campaign
Of the 361 victim IP addresses identified, Germany (55), the United States (41), Turkey (38), Iran (26), and France (25) account for most infections. France's presence in this top 5 is a reminder that French companies aren't spared by international APT campaigns, even when France isn't specifically the primary target.
What to do
The lesson for any vendor managing infrastructure through a hypervisor
Infrastructure management layers (hypervisors, orchestrators, cloud consoles) are often audited less thoroughly than the applications they host, even though they concentrate a far greater compromise potential. An application-focused security audit that ignores the underlying infrastructure layer leaves a major blind spot.
What CleanIssue checks for
During a cloud/infrastructure security review, we assess the exposure and hardening of critical management consoles (vCenter and equivalents), not just the application deployed on top of them.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
macOS Screen Sharing CVE-2026-65400: Bypassing Authentication to Mine Cryptocurrency
CVE-2026-65400 (CVSS 9.8) lets a network-based attacker authenticate to macOS Screen Sharing without valid credentials. The flaw was exploited to deploy Monero cryptocurrency miners before being added to CISA's KEV catalog.
SonicWall SMA 1000 CVE-2026-15409: A CVSS 10.0 Flaw Exploited by INC Ransomware
CVE-2026-15409 (CVSS 10.0), an unauthenticated SSRF in SonicWall SMA 1000 VPN gateways, chained with a code injection flaw to gain root access. The INC ransomware group has made it its primary entry vector since early August 2026.
Cl0p + PTC Windchill/FlexPLM CVE-2026-12569: a ransomware chain on enterprise PLM
Cl0p affiliates are chaining a pre-auth info-disclosure in FlexPLM's WSDL with a server-side flaw in the Windchill login servlet for unauthenticated RCE (CVE-2026-12569, CVSS 9.3) on internet-exposed PTC instances, deploying JSP webshells and staging engineering data for double extortion.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.