logo

CISA: VMware ESXi flaw now exploited in ransomware attacks

ID: 9fbd6e32-52f9-5e8c-894e-f4697dffeb19

STIX ID: report--9fbd6e32-52f9-5e8c-894e-f4697dffeb19

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-02-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA and Broadcom confirmed that a high-severity VMware ESXi sandbox escape vulnerability (CVE-2025-22225), patched in March 2025 alongside related zero-days, has been actively exploited — including in ransomware campaigns — with reporting that Chinese-speaking actors likely chained these flaws in attacks since early 2024; CISA added the flaw to its KEV catalog and mandated remediation for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.