logo

VMware Vulnerabilities Exploited

Multiple reports document critical vCenter and ESXi flaws—including DCE/RPC heap overflows and ESXi VM‑escape zero‑days—being actively exploited (often to achieve remote code execution, VM escape, ransomware deployment, or persistent backdoors), prompting urgent patching and hardening.

List of posts related to this topic

Post TitleDate PublishedDescribes IncidentFeed
CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks2026-02-05TruecybersecurityNews.com
Not Subscribed
CVE-2025-22225 in VMware ESXi now used in active ransomware attacks2026-02-04TrueSecurity Affairs
Not Subscribed
CISA Flags Actively Exploited VMware vCenter RCE Flaw in KEV Catalog2026-01-27TrueThe Cyber Express
Not Subscribed
CISA says critical VMware RCE flaw now actively exploited2026-01-26TrueBleeping Computer
Not Subscribed
CISA Alert: Critical VMware vCenter RCE (CVSS 9.8) Now Exploited in the Wild2026-01-25Truesecurityonline.info
Not Subscribed
CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks2026-01-24TruecybersecurityNews.com
Not Subscribed
U.S. CISA adds a flaw in Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities catalog2026-01-24TrueSecurity Affairs
Not Subscribed
Patch or die: VMware vCenter Server bug fixed in 2024 under attack today2026-01-23TrueThe Register (Security)
Not Subscribed
China-linked cybercrims abused VMware ESXi zero-days a year before disclosure2026-01-09TrueThe Register (Security)
Not Subscribed
Chinese-speaking hackers exploited ESXi zero-days long before disclosure2026-01-09TrueSecurity Affairs
Not Subscribed
“VM Isolation is Not Absolute”: Researchers Unmask Sophisticated ESXi “Maestro” Exploit2026-01-08Truesecurityonline.info
Not Subscribed
ESXi Exploitation in the Wild2026-01-07TrueHuntress Blog
Not Subscribed
Zero-Days Put Tens of 1,000s of Orgs at Risk for VM Escape Attacks2025-03-07TrueDark Reading
Not Subscribed
Over 37,000 VMware ESXi servers vulnerable to ongoing attacks2025-03-06TrueBleeping Computer
Not Subscribed
Three Zero-Day Vulnerabilities Discovered in VMware Products2025-03-05TrueCybereason Blog
Not Subscribed
Broadcom urges VMware customers to patch ‘emergency’ zero-day bugs under active exploitation2025-03-05TrueTechCrunch Security News
Not Subscribed
3 VMware Zero-Day Bugs Allow Sandbox Escape2025-03-04TrueDark Reading
Not Subscribed
CISA, VMware warn of new vulnerabilities being exploited by hackers2025-03-04TrueThe Record from Recorded Future News
Not Subscribed
VMware splats guest-to-hypervisor escape bugs already exploited in wild2025-03-04TrueThe Register (Security)
Not Subscribed
Broadcom fixes three VMware zero-days exploited in attacks2025-03-04TrueBleeping Computer
Not Subscribed
Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble2024-11-18TrueThe Register (Security)
Not Subscribed
Critical RCE bug in VMware vCenter Server now exploited in attacks2024-11-18TrueBleeping Computer
Not Subscribed
VMware fixes critical RCE, make-me-root bugs in vCenter - for the second time2024-10-22TrueThe Register (Security)
Not Subscribed
VMware fixes bad patch for critical vCenter Server RCE flaw2024-10-22TrueBleeping Computer
Not Subscribed
VMware Product Security Update Advisory (CVE-2024-38812, CVE-2024-38813)2024-09-18TrueASEC
Not Subscribed
VMware patches remote make-me-root holes in vCenter Server, Cloud Foundation2024-09-17TrueThe Register (Security)
Not Subscribed
Broadcom fixes critical RCE bug in VMware vCenter Server2024-09-17TrueBleeping Computer
Not Subscribed
June 18, 2024: Heap Overflow Vulnerabilities in VMWare vCenter Server2024-06-18TrueCensys Blog
Not Subscribed
Critical VMware Bugs Open Swaths of VMs to RCE, Data Theft2024-06-18TrueDark Reading
Not Subscribed
VMware fixes critical vCenter RCE vulnerability, patch now2024-06-18TrueBleeping Computer
Not Subscribed
VMware Issues Patches for Cloud Foundation, vCenter Server, and vSphere ESXi2024-06-18TrueThe Hacker News
Not Subscribed
VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug2024-06-18TrueThe Register (Security)
Not Subscribed
Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern2024-05-23TrueThe Hacker News
Not Subscribed
VMware urges emergency action to blunt hypervisor flaws2024-03-07TrueThe Register (Security)
Not Subscribed
VMware confirms critical vCenter flaw now exploited in attacks2024-01-19TrueBleeping Computer
Not Subscribed
ESXWhy: A Look at ESXiArgs Ransomware2023-02-09TrueCensys Blog
Not Subscribed
Analysis of Files Used in ESXiArgs Ransomware Attack Against VMware ESXi Servers2023-02-09TrueCloudSEK Blog
Not Subscribed

1–37 of 37