The Patches Are Ready. The Attackers Were Faster.
# The Patches Are Ready. The Attackers Were Faster.
Babuk ransomware in your VMware vCenter. That is what pages you at 3am. It is not a theoretical risk. Two separate flaws, CVE-2026-59310 and CVE-2026-59309, are being used by China-nexus actors to drop payloads. If you manage a virtualized environment, this is your first priority.
The second-order effect here is the force multiplier. A vCenter compromise isn't just one server going dark; it is the keys to every single VM on that cluster. You aren't losing a node; you're losing the whole neighborhood.
Then there is the WinSock flaw, CVE-2026-68820. Nine separate reports hit my desk this week alone. Lazarus isn't playing around with PoCs; they are using it for SYSTEM access and deploying backdoors. The federal patch deadline is August 25. If you wait until the 24th to start your change window, you've already lost.
Cisco ASA and Metabase users are in a worse spot. Both CVE-2026-20349 and CVE-2026-72898 hit the CISA KEV with federal deadlines of August 14. That was three days ago. If you haven't verified these patches, your perimeter is likely already a door. I don't care what the vendor severity rating says; if it's in the KEV and the deadline passed, it's a critical failure.
The SAP Commerce Cloud situation (CVE-2026-58231) proves my point about the "patch and pray" mentality. Exploitation attempts started just days after the patch dropped.
Here is where I take a stand: patching after an exploit is public is often performative security. If the attackers are already in, a patch just locks the door while they're already sitting in your living room. You cannot simply update the binary and call it a day. You have to hunt for dwell time first. Check your logs for indicators of compromise before you apply the fix, or you're just updating the OS for the attacker.
The priority list is simple:
1. VMware vCenter (Active ransomware deployment).
2. WinSock (Lazarus / SYSTEM access).
3. Cisco ASA and Metabase (KEV deadlines already passed).
4. SAP Commerce Cloud (High exploitation rate post-patch).
5. SharePoint Authentication Bypass (Public PoC exists).
As for the rest, it can wait.
Apple’s macOS Screen Sharing flaw, CVE-2026-65400, is making rounds. It's being used to install Monero miners on internet-exposed Macs. While a system-wide cryptominer is an annoyance and a signal of compromise, it doesn't compare to Babuk wiping your SAN. If you have to choose between fixing your Mac fleet or securing your hypervisors, pick the hypervisors every time.
The real question nobody is pricing in is how many "managed" providers are sitting on these vCenter flaws for their clients. We saw a similar pattern with managed database providers recently. The risk isn't just your internal stack; it's the third-party provider who told you their environment was secure but hasn't touched their VMware updates since July.
If you're still staring at a CVSS score to decide your Tuesday, you're doing it wrong. Look at the KEV and look at what Lazarus is doing. Everything else is just noise until the core is stable.
Check your vCenter logs for unusual account creation. Then check them again.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Recent macOS Screen Sharing Vulnerability Exploited in Attacks SecurityWeek
- Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure SecurityWeek
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware The Hacker News
- SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch The Hacker News
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner The Hacker News
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE The Hacker News
- Massive Azure Breach Hits McDonald’s, Vodafone, TCS and More - SQ Magazine Google News Security
- Fortune 500 Companies Hit in Azure Data Theft Campaign SecurityWeek