logo

Broadcom patches critical VMware flaws exploited at Pwn2Own Berlin 2025

ID: f02a7df9-74d1-56e8-a176-f0c59f7670ca

STIX ID: report--f02a7df9-74d1-56e8-a176-f0c59f7670ca

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2025-07-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Broadcom released patches for four critical VMware vulnerabilities (CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, CVE-2025-41239) that were exploited by researchers at Pwn2Own Berlin 2025 to achieve guest-to-host code execution and information disclosure; researchers earned substantial prizes for the exploits, and Broadcom reports no evidence of exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.