logo

Over 37,000 VMware ESXi servers vulnerable to ongoing attacks

ID: e7fcccb4-ce6e-50e8-b44f-ff8f827c7ee8

STIX ID: report--e7fcccb4-ce6e-50e8-b44f-ff8f827c7ee8

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-03-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A critical VCMI heap overflow (CVE-2025-22224) in VMware ESXi enabling guest-to-host escape is being actively exploited as a zero-day; Shadowserver reports roughly 37,000 internet-exposed ESXi instances remain vulnerable. Broadcom released fixes (also addressing CVE-2025-22225 and CVE-2025-22226), Microsoft observed the exploits in the wild, and CISA issued guidance requiring patching or mitigation by March 25, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.