VMware vCenter CVE-2026-59310: China-Linked APT Exploits Critical Flaw, France in the Top 5 Victims
> TL;DR: CVE-2026-59310 (CVSS 9.8) is a path traversal flaw in VMware vCenter that lets an attacker with network access to vCenter execute arbitrary code. CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026. A suspected China-nexus actor has been exploiting it to deploy persistent backdoors and, in at least one case, a Babuk-derived ransomware. France ranks among the most affected countries, with 25 compromised IP addresses out of 361 total across 47 countries.
Why vCenter is such a high-value target
VMware vCenter is the centralized management console for enterprise virtualization infrastructure. Compromising vCenter potentially means compromising every virtual machine it manages — application servers, databases, production environments. It's an extremely high-value pivot point: a single compromised server can grant access to dozens or hundreds of VMs.
The observed attack chain
Geographic breakdown of the campaign
Of the 361 victim IP addresses identified, Germany (55), the United States (41), Turkey (38), Iran (26), and France (25) account for most infections. France's presence in this top 5 is a reminder that French companies aren't spared by international APT campaigns, even when France isn't specifically the primary target.
What to do
The lesson for any vendor managing infrastructure through a hypervisor
Infrastructure management layers (hypervisors, orchestrators, cloud consoles) are often audited less thoroughly than the applications they host, even though they concentrate a far greater compromise potential. An application-focused security audit that ignores the underlying infrastructure layer leaves a major blind spot.
What CleanIssue checks for
During a cloud/infrastructure security review, we assess the exposure and hardening of critical management consoles (vCenter and equivalents), not just the application deployed on top of them.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
macOS Screen Sharing CVE-2026-65400: Bypassing Authentication to Mine Cryptocurrency
CVE-2026-65400 (CVSS 9.8) lets a network-based attacker authenticate to macOS Screen Sharing without valid credentials. The flaw was exploited to deploy Monero cryptocurrency miners before being added to CISA's KEV catalog.
SonicWall SMA 1000 CVE-2026-15409: A CVSS 10.0 Flaw Exploited by INC Ransomware
CVE-2026-15409 (CVSS 10.0), an unauthenticated SSRF in SonicWall SMA 1000 VPN gateways, chained with a code injection flaw to gain root access. The INC ransomware group has made it its primary entry vector since early August 2026.
Cisco FMC CVE-2026-20079: Three Attacker Clusters, from Web Shells to Qilin Ransomware via Sandworm
Cisco Talos documents three clusters exploiting patched Secure Firewall Management Center flaws: CVE-2026-20079 (CVSS 10.0 auth bypass leading to root) and CVE-2026-20316 (5.3 low-privilege access as entry). Web shells and credential theft, a Cyclops Blink implant linked to Sandworm, and a full Qilin deployment through legitimate FMC tooling. KEV deadline: September 12.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.