Vulnerability Details
CVE-2026-59310 is a critical directory traversal vulnerability in the VMware vCenter Syslog server that allows an attacker with network access to the appliance to execute arbitrary code, and it is being exploited at a global scale by a suspected China-nexus advanced persistent threat actor. Broadcom disclosed the flaw on July 29, 2026, in advisory VMSA-2026-0006 alongside CVE-2026-59309, an authentication bypass in the VMware Directory Service, and stated that no workaround exists.
Exploitation began five calendar days later. The first compromised systems connected to actor infrastructure on August 3, 2026, with the campaign expanding sharply on August 4 when 151 additional victim IP addresses appeared and reaching 343 of an eventual 361 unique victim IP addresses by August 5. Those 361 addresses span 47 countries, concentrated in Germany with 55, the United States with 41, Turkey with 38, Iran with 26, and France with 25, and cluster by sector in technology, software and cybersecurity, followed by higher education and research, and then telecommunications.
The observed intrusion chain abuses the syslog path-handling behavior to write actor-controlled content into /etc/cron.d, giving the actor immediate non-interactive code execution as root on the vCenter Server Appliance without any prior authentication event. From there, the actor stages the linuxFile WebSocket backdoor and the open-source reverse_ssh framework, plants a JSP webshell inside the vCenter Perfcharts application, grants the perfcharts service account passwordless sudo, harvests the vCenter machine account credential from the vmdir registry hive, creates multiple vSphere SSO administrator accounts, and ultimately deploys Babuk-derived ransomware against ESXi hosts.
With moderate confidence the operator is a Chinese-speaking actor probably working in a UTC+8 environment, based on Simplified Chinese artifacts in attacker scripts, apparent reuse of research from a Chinese security publication, repeated use of Chinese-language tooling, victimology that excludes mainland China, and activity patterns consistent with UTC+8 working hours — while noting insufficient evidence to associate the campaign with a named Chinese threat group or to determine state direction.
The root cause is insufficient constraints on pathnames handled by the vCenter Server Appliance syslog service, which allows relative traversal sequences supplied in log data to escape the configured syslog output directory. Recovered log entries preserve the exploit format, in which a traversal string of the form ../../../../etc/cron.d/zz-poc59310 appears embedded in a malformed syslog record accompanied by a crontab-formatted payload line and a fabricated timestamp dated to January 2026.
The effect is that actor-controlled content is written into a privileged execution location. Because the syslog service runs with sufficient privilege on the appliance, the resulting file is picked up and executed by the cron daemon in a root context, converting what is nominally a file write primitive into unauthenticated remote code execution as root against CVE-2026-59310.
Affected Product Matrix
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-59310 | VMware vCenter (9.1.x.x, 9.0.x.x, 8.0, 7.0), VMware Cloud Foundation (9.1.x.x, 9.0.x.x, 5.x), VMware vSphere Foundation (9.1.x.x, 9.0.x.x) | cpe:2.3:a:vmware:vcenter_server:*:*:*:*:*:*:*:* | CWE-22 |
CVE-2026-59309 | VMware Telco Cloud Platform (3.0, 4.x, 5.0.x, 5.1.x), VMware Telco Cloud Infrastructure (3.0) | cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* | CWE-303 |
Recommendations
Apply the fixed release identified in the VMSA-2026-0006 response matrix without delay: vCenter 9.1.0.0300 for the 9.1 branch, 9.0.2.0100 for the 9.0 branch, and 8.0 U3k or 8.0 U2f for the 8.0 branch. VMware Cloud Foundation 5.x requires an asynchronous patch to vCenter 8.0 U3k. Broadcom states no workaround exists for CVE-2026-59310.
Patching does not evict an actor who exploited the flaw before the update was applied, because persistence via reverse_ssh, systemd services, cron jobs and SSH keys survives the upgrade. Prioritize inspection of /etc/cron.d for files carrying poc59310 naming patterns, cron entries impersonating VMware services, unexpected systemd units, and any file named vmware-perf-update.jsp under the Perfcharts statsreport directories.
The observed intrusion created multiple administrative identities, including an SSO account named adminuser, a second account named vcadmin, and local adminuser accounts on individual ESXi hosts. Enumerate all vSphere SSO principals and local ESXi accounts, validate each against your authorized inventory, remove anything unrecognized, and rotate credentials for legitimate administrative accounts.
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
SHA256 | 6687083075c0dfcd86d4e0f5541550e29987de5e729efd5687ab0db1cd116b2c |
SHA1 | e876ceb47ba092420a97724a957152b3808568b0 |
IPv4 | 5[.]34[.]176[.]100 |
| 5[.]34[.]177[.]38 | |
| 78[.]135[.]91[.]204 | |
| 141[.]95[.]158[.]73 | |
| 146[.]56[.]116[.]119 | |
| 146[.]59[.]252[.]178 | |
| 185[.]144[.]28[.]120 | |
| 192[.]255[.]141[.]13 | |
IPv4:Port | 5[.]34[.]176[.]100[:]5244 |
| 5[.]34[.]177[.]38[:]9564 | |
| 5[.]34[.]177[.]38[:]9861 | |
| 185[.]144[.]28[.]120[:]3232 | |
| 192[.]255[.]141[.]13[:]7788 | |
| 192[.]255[.]141[.]13[:]8080 | |
Domains | intel[.]se9ly9upbhay[.]shop |
| se9ly9upbhay[.]shop | |
| profound-beijinho-504b1f[.]netlify[.]app | |
URLs | hxxp[:]//5[.]34[.]177[.]38[:]9861/linuxFile |
| hxxp[:]//5[.]34[.]177[.]38[:]9564/linuxFile | |
| hxxp[:]//185[.]144[.]28[.]120[:]3232/esxi[.]sh | |
| hxxp[:]//185[.]144[.]28[.]120[:]3232/esxi_amd64 | |
| hxxps[:]//tmpfiles[.]org/dl/1785758754[.]8cc04603f0b76caa/wqwNICA6Rb9o/systemlog[.]txt | |
| hxxps[:]//profound-beijinho-504b1f[.]netlify[.]app/f | |
| ws[:]//intel[.]se9ly9upbhay[.]shop[:]8080/ws | |
Email | pikpak0066test[@]outlook[.]com |
Hostname | kali[.]kali |
Filename | linuxFile |
| systemlog | |
| systemlog.txt | |
| linux_x86 | |
| esxi.sh | |
| esxi_amd64 | |
| backup | |
| run.sh | |
| _post_launch.sh | |
| zz-poc59310 | |
| zz-poc59310-syslog.log | |
| vmware-perf-update.jsp | |
| sso_domain.txt | |
| tmpclean | |
File Path | /etc/cron.d/zz-poc59310 |
| /etc/cron.d/zz-poc59310-syslog.log | |
| /etc/sudoers.d/vmware-perf | |
| /tmp/linuxFile | |
| /tmp/.x/ | |
| /tmp/.x/systemlog | |
| /tmp.x/systemlog | |
| /tmp/.x.py | |
| /tmp/.a.ldif | |
| /tmp/.ldap.out | |
| /tmp/.ldappw | |
| /tmp/.sso_domain | |
| /tmp/.vmware-perf-upd.sh | |
| /var/run/backup | |
| /usr/local/bin/tmpclean | |
| /root/.local/share/cg4nQW9TOxeq/ | |
| /usr/lib/vmware-perfcharts/tc-instance/webapps/statsreport/vmware-perf-update.jsp | |
User Agent | GoodMoodle-VCProbe/1.0 |
| GoodMoodle-VCFleet/1.0 | |
Service Name | sys-9436d8.service |
| network-manager | |
Account Name | adminuser |
| vcadmin | |
| vcenter_admin | |
| svc_dAi7dDGBKk | |
File Extension | .babyk |
Potential MITRE ATT&CK TTPs
T1588.002T1583.004T1583.006T1190T1053.003T1059.004T1059.006T1543.002T1053.003T1505.003T1098.004T1136.002T1136.001T1078.002T1548.003T1036.005T1564.001T1070.004T1027T1140T1497T1222.002T1562.001T1552.002T1082T1057T1021.004T1105T1219T1071.001T1572T1573T1102T1489T1486T1490References & Patch Links
Patch Link
References
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- https://medium.com/@quirso_de/the-great-clean-up-job-337ccefd2bee
- https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d
- https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
