A single directory traversal bug in VMware vCenter Server has turned into one of the broadest hypervisor‑level ransomware campaigns of 2026, affecting 361 victim IP addresses across 47 countries.
A single directory‑traversal vulnerability in VMware vCenter Server has ignited one of the most widespread hypervisor‑level ransomware campaigns of 2026, compromising 361 IP addresses across 47 nations.
The vulnerability and its exploitation
The flaw, tracked as CVE‑2026‑59310, allows an unauthenticated attacker to read arbitrary files on the vCenter host by supplying a crafted path in a REST API request. Exploit code published on underground forums quickly enabled threat actors to deploy the Babuk ransomware family directly onto vulnerable hypervisors.
Scope of the attack
Since the vulnerability’s disclosure in early March, security researchers have observed malicious traffic targeting vCenter instances in 47 countries, ranging from large enterprises to small‑to‑medium businesses. The campaign’s breadth is notable for its focus on hypervisor infrastructure, bypassing traditional endpoint defenses.
- 361 unique victim IP addresses identified
- Targets span North America, Europe, Asia‑Pacific, Africa and South America
- Ransom demands typically range from 5 to 15 BTC per compromised host
Mitigation and response
VMware released patches for all supported vCenter versions within days of the advisory, urging administrators to apply updates immediately and to enforce strict network segmentation for management interfaces. Organizations are also advised to audit logs for anomalous API calls and to verify the integrity of virtual machine snapshots.
"The rapid weaponization of this directory‑traversal bug underscores the critical need for timely patch management in virtualized environments," said a senior analyst at a leading cybersecurity firm.
Affected entities should also consider offline backups and immutable storage solutions to mitigate the impact of potential ransomware encryption.
Tech Insider coverage of VMware vCenter CVE‑2026‑59310 and Babuk ransomware