Back to blog
CVEAPTransomwarecloudFrance

VMware vCenter CVE-2026-59310: China-Linked APT Exploits Critical Flaw, France in the Top 5 Victims

Published on 2026-08-186 min readCleanIssue

> TL;DR: CVE-2026-59310 (CVSS 9.8) is a path traversal flaw in VMware vCenter that lets an attacker with network access to vCenter execute arbitrary code. CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026. A suspected China-nexus actor has been exploiting it to deploy persistent backdoors and, in at least one case, a Babuk-derived ransomware. France ranks among the most affected countries, with 25 compromised IP addresses out of 361 total across 47 countries.

Why vCenter is such a high-value target

VMware vCenter is the centralized management console for enterprise virtualization infrastructure. Compromising vCenter potentially means compromising every virtual machine it manages — application servers, databases, production environments. It's an extremely high-value pivot point: a single compromised server can grant access to dozens or hundreds of VMs.

The observed attack chain

  • Exploiting the path traversal flaw to achieve code execution on the vCenter server.
  • Deploying a backdoor paired with reverse_ssh binaries, enabling persistent, discreet remote access even if the initial access is detected and cut off.
  • In some cases, deploying a Babuk-derived ransomware to monetize the access obtained.
  • Geographic breakdown of the campaign

    Of the 361 victim IP addresses identified, Germany (55), the United States (41), Turkey (38), Iran (26), and France (25) account for most infections. France's presence in this top 5 is a reminder that French companies aren't spared by international APT campaigns, even when France isn't specifically the primary target.

    What to do

  • Patch immediately any vCenter server per the official Broadcom/VMware advisory.
  • Audit vCenter logs for traces of suspicious command execution or unknown reverse_ssh processes.
  • Restrict network access to vCenter to the strict minimum — vCenter should never be directly reachable from the internet, and internal network access should be limited to dedicated admin workstations.
  • Monitor outbound connections from the vCenter server, which normally shouldn't correspond to any C2 traffic.
  • The lesson for any vendor managing infrastructure through a hypervisor

    Infrastructure management layers (hypervisors, orchestrators, cloud consoles) are often audited less thoroughly than the applications they host, even though they concentrate a far greater compromise potential. An application-focused security audit that ignores the underlying infrastructure layer leaves a major blind spot.

    What CleanIssue checks for

    During a cloud/infrastructure security review, we assess the exposure and hardening of critical management consoles (vCenter and equivalents), not just the application deployed on top of them.

    Key takeaways

  • A compromised infrastructure management console grants access to every system it manages — its exposure should be minimized as a top priority.
  • International APT campaigns hit French companies too, even without specific targeting.
  • A complete security audit must cover the infrastructure layer (hypervisors, orchestrators), not just the application.
  • Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit