logo

Three VMware Zero-Days Exploited—Are You At Risk?

ID: 593f9f91-0af7-5479-a41c-73ecf3fa2c5a

STIX ID: report--593f9f91-0af7-5479-a41c-73ecf3fa2c5a

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

## Executive Summary Broadcom/Microsoft (MSTIC) disclosed three zero-day VMware vulnerabilities (CVE-2024-22224/22225/22226) affecting ESXi, Workstation, and Fusion that enable arbitrary code execution, sandbox escapes via kernel writes, and information disclosure; CVSS scores range from 7.1 to 9.3. The vendor confirms real-world exploitation; patches and fixed versions for affected products have been published and organizations are advised to patch immediately and strengthen monitoring and access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.