logo

VMware plugs steal-my-credentials holes in Cloud Foundation

ID: 5e56259e-dfbc-5075-b6bd-0bade8636d6c

STIX ID: report--5e56259e-dfbc-5075-b6bd-0bade8636d6c

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-01-30

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Broadcom patched five vulnerabilities in VMware Aria Operations and Aria Operations for Logs (components of VMware Cloud Foundation), including an 8.5-rated information disclosure (CVE-2025-22218), two stored XSS bugs (CVE-2025-22219, CVE-2025-22221), a privilege-escalation issue (CVE-2025-22220), and another information disclosure in Aria Operations (CVE-2025-22222); exploitation requires authorized or compromised accounts, no active exploitation has been reported, and updates/KB92148 provide fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.