logo

CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks

ID: afd3b5ed-5448-5df9-9960-a1295c65f785

STIX ID: report--afd3b5ed-5448-5df9-9960-a1295c65f785

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA and Broadcom-confirmed zero-day vulnerabilities in VMware ESXi (notably CVE-2025-22225 with CVSS 8.2 and related CVEs) are being exploited in the wild to escape VM isolation and deploy ransomware and hypervisor backdoors; CISA added CVE-2025-22225 to its KEV catalog, many ESXi instances remain exposed, and the report urges immediate patching, privilege restriction, EDR monitoring for VMX anomalies, and scanning for IOCs like unsigned drivers and VSOCK traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.