// threat intel

VMware vCenter Flaw (CVE-2026-59310) Exploited to Deploy Babuk-Derived Ransomware

VMware vCenter Flaw (CVE-2026-59310) Exploited to Deploy Babuk-Derived Ransomware — security advisory

Attackers are exploiting CVE-2026-59310, a severe directory-traversal vulnerability in VMware vCenter, to deploy Babuk-derived ransomware. Internet-exposed management interfaces remain a favourite ransomware entry point.

The gap between “patch available” and “patched everywhere” is precisely where ransomware crews operate.

Our analysis

vCenter is a crown-jewel target: control it and you control every VM, snapshot and backup beneath it. That is why ransomware crews weaponise vCenter bugs within days — it is the fastest route to encrypting an entire estate at once. A directory-traversal foothold here does not stay small; it becomes total. If your virtualization management plane is reachable from the internet, treat that as the emergency, independent of this specific CVE.

What you should do

  • Patch vCenter and ESXi immediately, and never expose management interfaces to the internet.
  • Segment and isolate the management plane; require MFA and jump hosts for administrative access.
  • Maintain offline, immutable backups that ransomware cannot reach through vCenter.
  • Validate your perimeter and detection with a red-team exercise, not just a vulnerability scan.

How AgentOffense helps: our external network penetration testing validates your perimeter exposure, and red team operations test whether you would actually detect and stop a real intrusion.

Source: The Hacker News / Cybersecurity Insiders.

Why hypervisor bugs are ransomware gold

Ransomware crews target virtualisation management because it collapses the whole attack chain into one step. Instead of encrypting hundreds of machines individually, they compromise vCenter and encrypt every VM’s underlying storage at once — or simply power off the estate and hold it hostage.

These flaws are exploited within days of disclosure precisely because the payoff is so high. The defensive question is not just ‘are we patched?’ but ‘if an attacker gets a foothold on any internal host, can they reach the management plane at all?’ — which only assumed-breach testing answers.

What this means for your business

Virtualisation management is a crown-jewel target: control vCenter and you control every VM. Ransomware crews exploit these flaws precisely because one unpatched host yields the whole estate. Internal exposure of hypervisor management is a business-ending risk.

How to reduce your exposure

  • Patch hypervisor and management planes on an emergency cadence.
  • Segment and restrict management interfaces; never expose them broadly internally.
  • Enforce MFA and least-privilege on virtualisation admin access.
  • Validate that an attacker with a foothold cannot pivot to management.

Test lateral movement and blast radius with internal network penetration testing — get a fixed-price quote.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement