VMware News Articles

Recent news articles refferecing the vendors vulnerabilities.

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.

4 days ago

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Hackers are exploiting CVE-2026–59310, a critical vulnerability in VMware vCenter that leads to arbitrary code execution.

4 days ago

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access - SwapUpdate

Ravie LakshmananAug 12, 2026Vulnerability / Threat Intelligence

5 days ago

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.

5 days ago

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.

3 weeks ago

CISA: VMware ESXi flaw now exploited in ransomware attacks

CISA confirmed on Wednesday that ransomware gangs have begun exploiting a high-severity VMware ESXi sandbox escape vulnerability that was previously used in zero-day attacks.

CISA says critical VMware RCE flaw now actively exploited

CISA has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered U.S. federal agencies to secure their servers within three weeks.

CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog

CISA added VMware vCenter vulnerability CVE-2024-37079 to its KEV list after confirmed in-the-wild exploitation, urging organizations to apply patches

Exploit for VMware Zero-Day Flaws Likely Built a Year Before Public Disclosure

Analysis of a recent attack targeting VMware ESXi vulnerabilities from March 2025 revealed an exploit developed a year before disclosure.

Exploit for VMware Zero-Day Flaws Likely Built a Year Before Public Disclosure

Analysis of a recent attack targeting VMware ESXi vulnerabilities from March 2025 revealed an exploit developed a year before disclosure.

Xwiki and VMWare vulnerabilities exploited in the wild

A pair of newly exploited vulnerabilities has been added to CISA’s Known Exploited Vulnerabilities Catalog.

CISA adds VMware bug to KEV a year after first exploited

CISA updated its known exploited vulnerability catalogue on Thursday to include the VMware bug CVE-2025-41244, first exploited in October 2024.

CISA Warns of Actively Exploited 0-Day Vulnerabilities in VMware Tools and Aria Operations

Tracked as CVE-2025-41244, this 0-day flaw poses a significant risk to organizations managing virtualized infrastructure, potentially allowing attackers

CISA Warns of VMware Tools and Aria Operations 0-Day Vulnerability Exploited in Attacks

CISA has added CVE-2025-41244 to its Known Exploited Vulnerabilities catalog. This local privilege escalation flaw affects Broadcom's VMware Aria Operations and VMware Tools, with evidence of active exploitation in the wild.

U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds XWiki Platform, and Broadcom VMware Aria Operations and VMware Tools flaws to its Known Exploited Vulnerabilities catalog.

China Exploited New VMware Bug for Nearly a Year

A seemingly benign privilege-escalation process in VMware and other software has likely benefited attackers and other malware strains for years.

Chinese hackers exploiting VMware zero-day since October 2024

Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024.

Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024

VMware CVE-2025-41244 exploited by UNC5174 since Oct 2024, CVSS 7.8, patch now available.

CSA Issues Critical Alert For VMware Vulnerabilities

Broadcom and CSA warn of critical VMware Vulnerabilities ilties flaws, including CVE-2025-41236 and CVE-2025-41237. Update ESXi, Workstation, and Fusion immediately to stay secure.

Over 37,000 VMware ESXi servers vulnerable via CVE-2025-22224 | Born's Tech and Windows World

[German]This week, VMware by Broadcom has released security updates for various products, including VMware ESXi servers, to close security gaps. One vulnerability has already been exploited as a 0-day. Now...

Broadcom patches critical VMware flaws exploited at Pwn2Own Berlin 2025

VMware patched flaws disclosed during the Pwn2Own Berlin 2025 hacking contest, where researchers earned $340,000 for exploiting them.

Broadcom patches critical VMware flaws exploited at Pwn2Own Berlin 2025

VMware patched flaws disclosed during the Pwn2Own Berlin 2025 hacking contest, where researchers earned $340,000 for exploiting them.

VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin

VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.

Multiple Vulnerabilities in VMware Products

Security updates have been released for multiple vulnerabilities affecting VMware products.

0-day vulnerabilities in VMWare ESXi, Workstation and Fusion | Born's Tech and Windows World

[German]As of March 4, 2025, VMware by Broadcom has published a security advisory to warn of three zero-day vulnerabilities CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226) that have already been exploited...

No more news articles to load.