- The Mess: A critical flaw in VMware vCenter Server, tracked as CVE-2026-59310, is being actively exploited. The vulnerability carries a CVSS score of 9.8, and attacks have been linked to ransomware activity.
The target is not some obscure desktop application. vCenter sits at the center of VMware environments and controls virtual infrastructure. Compromise the management layer and the attacker can potentially reach a very large number of virtual machines from one place.
That is what makes this bug particularly nasty.
Security researchers have reported exploitation across multiple countries, with the activity associated with attacks involving Babuk ransomware. Once attackers get control of the virtualization management environment, the blast radius can become enormous.
- The Damage: A compromised vCenter server can give attackers a powerful position inside the virtualization stack, potentially allowing them to target virtual machines, steal sensitive data, disrupt services and deploy ransomware across an entire environment.
One vulnerable management server can effectively become the keys to a whole virtual datacenter.
That is a much bigger problem than losing one Windows workstation.
Virtualization exists partly to centralize management. Attackers love that idea too.
- The Fix: Patch affected VMware vCenter Server installations immediately, restrict management interfaces to trusted administration networks, monitor authentication and administrative activity, and investigate systems for signs of compromise before assuming that applying the patch alone solved the problem.
Bugstoday Opinion
This is exactly why management interfaces should never be treated like ordinary servers.
One vCenter compromise can turn dozens or hundreds of virtual machines into sitting ducks. Add ransomware and suddenly the incident-response team has a very expensive morning.
A CVSS 9.8 vulnerability being actively exploited in virtualization infrastructure is not something to put into the “patch next weekend” pile.
Bugstoday verdict: patch vCenter now. Then check whether the attackers were already inside.



