VMware vCenter Flaw Actively Exploited: 55 IPs in Germany Hit

Step by step
How the attack unfolded
Click a phase for details – or let the animation play through.
PHASE 1/6 · Initial Access

A suspected China-nexus group exploits a critical directory-traversal flaw in Broadcom VMware vCenter Server.

T1190 – Exploit Public-Facing Application
  • CVE-2026-59310 (directory traversal / code execution)
  • additional activity around CVE-2026-59309
  • affected: vCenter Server and vCenter Server Appliance
  • internet-exposed management interface targeted
PHASE 2/6 · Execution

Via the directory-traversal path the attackers inject and run their own code, fully taking over vCenter.

T1059 – Command and Scripting Interpreter
  • remote code execution on the vCenter server
  • full takeover of the central management hub
  • potential access to all managed VMs
PHASE 3/6 · Privilege Escalation

The actors create new privileged user accounts to secure administrative access.

T1136 – Create Account
  • newly created accounts with far-reaching privileges
  • administrative access via own accounts
PHASE 4/6 · Persistence

Backdoors, web shells and privileged accounts ensure the attackers persist in the network.

T1505.003 – Server Software Component: Web Shell T1505 – Server Software Component
  • hidden backdoors persisting even after patching
  • browser-based web shells for control
  • persistent privileged user accounts
PHASE 5/6 · Evasion / Command-and-Control

Via reverse SSH the compromised server establishes outbound connections, bypassing many firewalls.

T1572 – Protocol Tunneling
  • reverse SSH remote-access connection outbound
  • outbound traffic often less strictly monitored
  • concealment of attacker presence
PHASE 6/6 · Impact

On at least one ESXi system a Babuk-derived ransomware was deployed, encrypting data.

T1486 – Data Encrypted for Impact
  • Babuk-derived ransomware on ESXi host
  • data encryption and operational outage
  • 361 compromised IPs across 47 countries, 55 in Germany
Short & clear answers
Frequently asked questions about this incident
Am I affected by this vCenter attack wave?
Affected companies are those running VMware vCenter Server or the vCenter Server Appliance from Broadcom – especially if the management interface is reachable from the internet. So far, 361 compromised IP addresses have been counted across 47 countries, 55 of them in Germany. If you run a virtualized server landscape via vCenter and it is publicly accessible, you are in the immediate target group.
What do I need to do right now?
Disconnect the vCenter management interface from the internet and restrict access to internal networks or a VPN. Monitor Broadcom/VMware's official security advisories regarding CVE-2026-59310 and CVE-2026-59309 and apply updates immediately once available. Additionally, actively check for backdoors and secure working, network-isolated backups.
Is applying the patch enough to be safe?
No. The attackers set up backdoors, reverse SSH connections, webshells and new privileged accounts that persist even after the vulnerability is closed. Simply applying updates does not remove these already-installed backdoors. You must additionally search specifically for such access points and remove suspicious accounts.
How can I tell if my system has already been compromised?
Watch for unknown user accounts with high privileges, unusual outbound connections (reverse SSH), and unexplained files in the web directory (webshells). Also include the associated ESXi hosts in your check, since ransomware was deployed on at least one of them. Because the access points are concealed, you should bring in a specialized service provider if in doubt.
What specific damage can a successful attack cause?
vCenter is the central control hub of a VMware environment – whoever takes control there can typically access all managed virtual servers. On at least one examined ESXi system, ransomware derived from Babuk was deployed, encrypting data and paralyzing operations. An attack therefore potentially affects your entire virtual infrastructure.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.