Suspected China-Nexus APT Weaponizes CVE-2026-59310

Red | Vuinerability
Suspected China-Nexus APT Weaponizes CVE-2026-59310

Summary

CVE-2026-59310 is a critical directory traversal flaw in the VMware vCenter Syslog server that allows an unauthenticated attacker with network access to write to /etc/cron.d and gain immediate root code execution on the appliance. Exploitation began five days after disclosure, and since then a suspected China-nexus APT has compromised 361 victim IPs across 47 countries, concentrated in Germany, the US, Turkey, Iran, and France, and skewed toward technology, higher education, and telecommunications.

The business impact of CVE-2026-59310 is severe because vCenter is the control plane for the entire virtual estate rather than a single application, so one unauthenticated remote code execution against it collapses the blast radius of the whole VMware environment into a single point of failure.

CVENameAffected ProductZero-DayCISA KEVPatch
CVE-2026-59310Broadcom VMware vCenter Path Traversal VulnerabilityBroadcom VMware vCenterAvailable
CVE-2026-59309Broadcom VMware vCenter Authentication Bypass VulnerabilityBroadcom VMware vCenterAvailable

Vulnerability Details

01

CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog server that allows an attacker with network access to the appliance to execute arbitrary code, and it is being exploited at a global scale by a suspected China-nexus advanced persistent threat actor. Broadcom disclosed the flaw on July 29, 2026, in advisory VMSA-2026-0006 alongside CVE-2026-59309, an authentication bypass in the VMware Directory Service, and stated that no workaround exists.

02

Exploitation began five calendar days later. The first compromised systems connected to actor infrastructure on August 3, 2026, with the campaign expanding sharply on August 4 when 151 additional victim IP addresses appeared and reaching 343 of an eventual 361 unique victim IP addresses by August 5. Those 361 addresses span 47 countries, concentrated in Germany with 55, the United States with 41, Turkey with 38, Iran with 26, and France with 25, and cluster by sector in technology, software and cybersecurity, followed by higher education and research, and then telecommunications.

03

The observed intrusion chain abuses the syslog path-handling behavior to write actor-controlled content into /etc/cron.d, giving the actor immediate non-interactive code execution as root on the vCenter Server Appliance without any prior authentication event. From there, the actor stages the linuxFile WebSocket backdoor and the open-source reverse_ssh framework, plants a JSP webshell inside the vCenter Perfcharts application, grants the perfcharts service account passwordless sudo, harvests the vCenter machine account credential from the vmdir registry hive, creates multiple vSphere SSO administrator accounts, and ultimately deploys Babuk-derived ransomware against ESXi hosts.

04

With moderate confidence the operator is a Chinese-speaking actor probably working in a UTC+8 environment, based on Simplified Chinese artifacts in attacker scripts, apparent reuse of research from a Chinese security publication, repeated use of Chinese-language tooling, victimology that excludes mainland China, and activity patterns consistent with UTC+8 working hours — while noting insufficient evidence to associate the campaign with a named Chinese threat group or to determine state direction.

05

The root cause is insufficient constraints on pathnames handled by the vCenter Server Appliance syslog service, which allows relative traversal sequences supplied in log data to escape the configured syslog output directory. Recovered log entries preserve the exploit format, in which a traversal string of the form ../../../../etc/cron.d/zz-poc59310 appears embedded in a malformed syslog record accompanied by a crontab-formatted payload line and a fabricated timestamp dated to January 2026.

06

The effect is that actor-controlled content is written into a privileged execution location. Because the syslog service runs with sufficient privilege on the appliance, the resulting file is picked up and executed by the cron daemon in a root context, converting what is nominally a file write primitive into unauthenticated remote code execution as root against CVE-2026-59310.

Affected Product Matrix
CVE IDAffected ProductsAffected CPECWE ID
CVE-2026-59310VMware vCenter (9.1.x.x, 9.0.x.x, 8.0, 7.0), VMware Cloud Foundation (9.1.x.x, 9.0.x.x, 5.x), VMware vSphere Foundation (9.1.x.x, 9.0.x.x)cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:*CWE-22
CVE-2026-59309VMware Telco Cloud Platform (3.0, 4.x, 5.0.x, 5.1.x), VMware Telco Cloud Infrastructure (3.0)cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:*CWE-303

Recommendations

STEP 01
Patch vCenter Immediately

Apply the fixed release identified in the VMSA-2026-0006 response matrix without delay: vCenter 9.1.0.0300 for the 9.1 branch, 9.0.2.0100 for the 9.0 branch, and 8.0 U3k or 8.0 U2f for the 8.0 branch. VMware Cloud Foundation 5.x requires an asynchronous patch to vCenter 8.0 U3k. Broadcom states no workaround exists for CVE-2026-59310.

STEP 02
Assume Compromise and Hunt Before Declaring Closure

Patching does not evict an actor who exploited the flaw before the update was applied, because persistence via reverse_ssh, systemd services, cron jobs and SSH keys survives the upgrade. Prioritize inspection of /etc/cron.d for files carrying poc59310 naming patterns, cron entries impersonating VMware services, unexpected systemd units, and any file named vmware-perf-update.jsp under the Perfcharts statsreport directories.

STEP 03
Audit vSphere SSO and ESXi Accounts for Unauthorized Identities

The observed intrusion created multiple administrative identities, including an SSO account named adminuser, a second account named vcadmin, and local adminuser accounts on individual ESXi hosts. Enumerate all vSphere SSO principals and local ESXi accounts, validate each against your authorized inventory, remove anything unrecognized, and rotate credentials for legitimate administrative accounts.


Indicators of Compromise (IoCs)

TypeValue
SHA2566687083075c0dfcd86d4e0f5541550e29987de5e729efd5687ab0db1cd116b2c
SHA1e876ceb47ba092420a97724a957152b3808568b0
IPv45[.]34[.]176[.]100
5[.]34[.]177[.]38
78[.]135[.]91[.]204
141[.]95[.]158[.]73
146[.]56[.]116[.]119
146[.]59[.]252[.]178
185[.]144[.]28[.]120
192[.]255[.]141[.]13
IPv4:Port5[.]34[.]176[.]100[:]5244
5[.]34[.]177[.]38[:]9564
5[.]34[.]177[.]38[:]9861
185[.]144[.]28[.]120[:]3232
192[.]255[.]141[.]13[:]7788
192[.]255[.]141[.]13[:]8080
Domainsintel[.]se9ly9upbhay[.]shop
se9ly9upbhay[.]shop
profound-beijinho-504b1f[.]netlify[.]app
URLshxxp[:]//5[.]34[.]177[.]38[:]9861/linuxFile
hxxp[:]//5[.]34[.]177[.]38[:]9564/linuxFile
hxxp[:]//185[.]144[.]28[.]120[:]3232/esxi[.]sh
hxxp[:]//185[.]144[.]28[.]120[:]3232/esxi_amd64
hxxps[:]//tmpfiles[.]org/dl/1785758754[.]8cc04603f0b76caa/wqwNICA6Rb9o/systemlog[.]txt
hxxps[:]//profound-beijinho-504b1f[.]netlify[.]app/f
ws[:]//intel[.]se9ly9upbhay[.]shop[:]8080/ws
Emailpikpak0066test[@]outlook[.]com
Hostnamekali[.]kali
FilenamelinuxFile
systemlog
systemlog.txt
linux_x86
esxi.sh
esxi_amd64
backup
run.sh
_post_launch.sh
zz-poc59310
zz-poc59310-syslog.log
vmware-perf-update.jsp
sso_domain.txt
tmpclean
File Path/etc/cron.d/zz-poc59310
/etc/cron.d/zz-poc59310-syslog.log
/etc/sudoers.d/vmware-perf
/tmp/linuxFile
/tmp/.x/
/tmp/.x/systemlog
/tmp.x/systemlog
/tmp/.x.py
/tmp/.a.ldif
/tmp/.ldap.out
/tmp/.ldappw
/tmp/.sso_domain
/tmp/.vmware-perf-upd.sh
/var/run/backup
/usr/local/bin/tmpclean
/root/.local/share/cg4nQW9TOxeq/
/usr/lib/vmware-perfcharts/tc-instance/webapps/statsreport/vmware-perf-update.jsp
User AgentGoodMoodle-VCProbe/1.0
GoodMoodle-VCFleet/1.0
Service Namesys-9436d8.service
network-manager
Account Nameadminuser
vcadmin
vcenter_admin
svc_dAi7dDGBKk
File Extension.babyk

Potential MITRE ATT&CK TTPs

T1588.002
Resource DevelopmentObtain Capabilities: Tool
T1583.004
Resource DevelopmentAcquire Infrastructure: Server
T1583.006
Resource DevelopmentAcquire Infrastructure: Web Services
T1190
Initial AccessExploit Public-Facing Application
T1053.003
ExecutionScheduled Task/Job: Cron
T1059.004
ExecutionCommand and Scripting Interpreter: Unix Shell
T1059.006
ExecutionCommand and Scripting Interpreter: Python
T1543.002
PersistenceCreate or Modify System Process: Systemd Service
T1053.003
PersistenceScheduled Task/Job: Cron
T1505.003
PersistenceServer Software Component: Web Shell
T1098.004
PersistenceAccount Manipulation: SSH Authorized Keys
T1136.002
PersistenceCreate Account: Domain Account
T1136.001
PersistenceCreate Account: Local Account
T1078.002
Privilege EscalationValid Accounts: Domain Accounts
T1548.003
Privilege EscalationAbuse Elevation Control Mechanism: Sudo and Sudo Caching
T1036.005
Defense EvasionMasquerading: Match Legitimate Name or Location
T1564.001
Defense EvasionHide Artifacts: Hidden Files and Directories
T1070.004
Defense EvasionIndicator Removal: File Deletion
T1027
Defense EvasionObfuscated Files or Information
T1140
Defense EvasionDeobfuscate/Decode Files or Information
T1497
Defense EvasionVirtualization/Sandbox Evasion
T1222.002
Defense EvasionFile and Directory Permissions Modification: Linux and Mac
T1562.001
Defense EvasionImpair Defenses: Disable or Modify Tools
T1552.002
Credential AccessUnsecured Credentials: Credentials in Registry
T1082
DiscoverySystem Information Discovery
T1057
DiscoveryProcess Discovery
T1021.004
Lateral MovementRemote Services: SSH
T1105
Command and ControlIngress Tool Transfer
T1219
Command and ControlRemote Access Software
T1071.001
Command and ControlApplication Layer Protocol: Web Protocols
T1572
Command and ControlProtocol Tunneling
T1573
Command and ControlEncrypted Channel
T1102
Command and ControlWeb Service
T1489
ImpactService Stop
T1486
ImpactData Encrypted for Impact
T1490
ImpactInhibit System Recovery

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.