logo

Broadcom fixes high-severity VMware NSX bugs reported by NSA

ID: a2ef8b09-4ce5-5b4c-bdc4-547d173fd995

STIX ID: report--a2ef8b09-4ce5-5b4c-bdc4-547d173fd995

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-09-30

Date Updated: 2026-07-19

Author: Sergiu Gatlan

...
...

Broadcom published security advisories and patches for multiple high-severity VMware vulnerabilities — including two NSX username-enumeration flaws (CVE-2025-41251, CVE-2025-41252), a vCenter SMTP header injection (CVE-2025-41250), and Aria/Tools issues that can enable privilege escalation and credential theft — noting contributions from the NSA and contextualizing the risk with past zero-days and active exploitation of VMware products by state and criminal actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.