Published on 18 August 2026
361 compromised IP addresses across 47 countries, 55 of them in Germany – that is the current tally of an attack wave that a group presumed to be close to China is running against VMware vCenter servers. Anyone running virtual machines on VMware infrastructure in their organisation should read this article to the end. Because after successfully breaking in, the attackers set up backdoors according to the available analyses – and on at least one examined system, ransomware was subsequently deployed, encrypting data and paralysing operations.
As The Hacker News reports, an attacker group presumed to be close to China is currently actively exploiting a critical security vulnerability in Broadcom VMware vCenter Server. The preconfigured variant, the vCenter Server Appliance, is also affected – that is, the ready-to-use virtual machine that many companies use to centrally manage their VMware environment.
At the centre of the attacks is the vulnerability with the identifier CVE-2026-59310. A CVE number (Common Vulnerabilities and Exposures) is the internationally unique catalogue number for a known security flaw. Additionally, the analyses point to activity surrounding a second vulnerability, CVE-2026-59309.
The implications are considerable: vCenter is the central control hub of a VMware environment. Whoever takes control there can usually access all managed virtual servers. A successful attack on vCenter therefore potentially affects a company's entire virtual infrastructure – not just a single server.
According to the report, the vulnerability CVE-2026-59310 enables code execution via so-called directory traversal. Both terms sound technical, but can be well explained using everyday images:
The combination of the two is especially dangerous: by way of the directory traversal detour, the attackers reach a point where they can inject and execute their own code. This makes a complete takeover of the vCenter server possible.
After successful access, the perpetrators did not settle for a one-time intrusion. According to the available analyses, they set up several mechanisms to remain in the network permanently and to disguise their presence:
Particularly alarming: on at least one examined ESXi system – ESXi is the VMware software that runs directly on the hardware and operates the virtual machines – a ransomware derived from Babuk was subsequently deployed. Ransomware is malware that encrypts data and demands a ransom for its release. In this case, the attack did not end at pure espionage, but led to active encryption and thus to the system going down.
Affected are companies that use VMware vCenter Server or the vCenter Server Appliance from Broadcom. This includes in particular organisations that run their server landscape in a virtualised manner – a model widespread among mid-sized companies.
The figures from the analysis make clear that this is not a purely theoretical risk:
Germany is thus among the more heavily affected countries. For you as a decision-maker, this means: if your company operates vCenter and it is reachable from the internet, you are part of the immediate target group of this attack wave.
Concrete technical checking steps are not available in the researched material. Nevertheless, sensible starting points for your IT staff can be derived from the described attack characteristics:
If you do not have your own IT security department, this is the moment to bring in a specialised service provider. Searching for the described backdoors requires experience – a superficial check is not enough when it comes to already active, disguised access points.
Since the material contains no concrete information on available patches, affected versions or an official timeline, the following recommendations focus on generally accepted immediate measures for actively exploited vulnerabilities of this category:
A compromised vCenter server is more than a technical nuisance. Because vCenter forms the central management of the virtual servers, a successful attack can affect the confidential data of all systems running on it – possibly including personal data of customers, employees or business partners.
If a breach occurs in which personal data could be affected, the notification obligations of the General Data Protection Regulation (GDPR) apply. Under Article 33 GDPR, controllers must generally report a personal data breach to the competent supervisory authority within 72 hours of becoming aware of it. Under certain conditions, the affected individuals must also be informed. The use of ransomware described in the report aggravates the situation further, since here, in addition to a possible data leak, the availability of the data is also directly impaired.
Therefore: as soon as your IT staff detect signs of an actual compromise, the data protection assessment should begin in parallel with the technical remediation – ideally together with your data protection officer.
The active exploitation of CVE-2026-59310 in VMware vCenter is a serious incident with a clear connection to Germany: 55 of the total 361 compromised IP addresses are located in Germany. The attackers do not limit themselves to a one-time intrusion, but set up persistent backdoors – and in at least one documented case this was followed by the deployment of ransomware.
For companies operating VMware infrastructure, this means: do not wait. Check whether your vCenter management is reachable from the internet, monitor Broadcom's security advisories on the named CVE identifiers, and have your environment specifically examined for the described attack traces. A current backup, separated from the network, is your most important insurance against the worst case.
This article is based on a report by The Hacker News. As soon as the vendor Broadcom names the specific affected versions and patches, you should incorporate this information into your measures without delay.