Desk live·
ForensicPost
Cloud/Exploitation/File 26-0810b

VMware vCenter Flaw Exploited in 47 Countries Within a Week of the Patch

Broadcom fixed CVE-2026-59310 on 29 July. Attackers began exploiting it on 3 August, and by 5 August around 95% of the victims one incident response firm counted — 361 addresses across 47 countries — had already been taken.

Constructed geometry · not a chart of case data
JurisdictionGermanyBerlinthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetVMware vCenter operators
ActorUnattributed
S. Rosler10 min readConfidence: medium3 sources reviewed

CVE-2026-59310 is a directory traversal flaw in the VMware vCenter Syslog service, rated CVSS 9.8, which lets an unauthenticated attacker with network access run arbitrary code. Broadcom released a fix on 29 July 2026.

The German incident response firm Quirso found an exploitation campaign during an engagement and published on 10 August. Compromised hosts first contacted attacker infrastructure on 3 August, five days after the fix. By 5 August around 95% of the victims Quirso observed had appeared. The firm counted 361 victim IP addresses across 47 countries, more than half in Germany, the United States, Turkey, Iran and France, with Babuk-derived ransomware deployed and reverse SSH access established.

The Window Was Two Days, Not Five

The interval that matters is not the five days between the patch and the first exploitation. It is the two days in which most of the damage was done.

An organisation that opened a change ticket on the Monday after disclosure had already missed it. Whatever the standard advice about prioritising critical patches is worth, the practical window here was shorter than most change-approval processes run.

vCenter Is Not An Application

A vCenter server administers the virtual machines underneath it. Code execution on it is not access to one system; it is authority over everything that console manages.

Management systems keep turning up at the start of these files — mobile device managers, print servers, self-service password tools. A hypervisor console belongs at the top of that list, and it is routinely reachable from the internet because administering it from elsewhere is convenient.

The Attribution Is A Working Pattern

Quirso assessed with moderate confidence that a Chinese-speaking actor ran the campaign, likely working in UTC+08:00. We are carrying that as the firm stated it and going no further.

Working hours and language artefacts are real evidence, and they are also the two easiest things to stage. Graded medium: the timeline and victim counts are well documented, the actor is not, and the counts describe one firm’s visibility rather than a census.

How we reported this

Compiled from Quirso’s published research, Broadcom’s advisory and public reporting, listed below. Victim counts are one firm’s visibility, not a census. The actor assessment is the researchers’ own, at moderate confidence. Corrections: corrections@forensicpost.com.

Sources
  1. vCenter Flaw Exploited Just Five Days After DisclosureInfosecurity Magazine
  2. Critical VMware vCenter RCE flaw exploited for reverse SSH accessBleepingComputer
  3. Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareThe Hacker News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary