Brand
VMware (Broadcom): actively exploited vulnerabilities
28 vulnerabilities in VMware (Broadcom) products (vCenter Server, ESXi, Workspace ONE Access / Identity Manager…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 18, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
4 vulnerabilities added in the last 12 months
-
28 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one VMware (Broadcom) category to your radar, or open its page.
- Virtualization, VDI and cloud 21 vulnerabilities
- Identity and access 3 vulnerabilities
- Monitoring, ITSM and asset management 3 vulnerabilities
- Switches, routers and SD-WAN 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- vCenter Server 12 vulnerabilities · Virtualization and VDI
- ESXi 6 vulnerabilities · Virtualization and VDI
- Workspace ONE Access / Identity Manager 3 vulnerabilities · Identity and access
- Aria Operations (ex-vRealize Operations) 2 vulnerabilities · Monitoring and ITSM
- VMware Tools 2 vulnerabilities · Virtualization and VDI
- Aria Operations for Networks (ex-vRealize Network Insight) 1 vulnerability · Monitoring and ITSM
- SD-WAN (VeloCloud) 1 vulnerability · Switches and routers
- Workstation / Fusion 1 vulnerability · Virtualization and VDI
Names used by CISA: Broadcom, VMware. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 1 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 1 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 1 |
| Apr 2, 2026 to May 1, 2026 | 0 |
| May 2, 2026 to May 31, 2026 | 0 |
| Jun 1, 2026 to Jun 30, 2026 | 0 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 1 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this VMware (Broadcom) list.
Rank 1VMware (Broadcom) vCenter Server
CVE-2026-59310Hunt for compromise (CISA)Ransomware
Broadcom VMware vCenter Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 18, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2VMware (Broadcom) vCenter Server
CVE-2024-37079CVE from 2024, added in 2026
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jan 23, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 3VMware (Broadcom) Aria Operations (ex-vRealize Operations)
CVE-2026-22719Broadcom VMware Aria Operations Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 3, 2026
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 4VMware (Broadcom) VMware Tools
CVE-2025-41244Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 30, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 5VMware (Broadcom) vCenter Server
CVE-2024-38812VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 20, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 6VMware (Broadcom) vCenter Server
CVE-2024-38813VMware vCenter Server Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 20, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 7VMware (Broadcom) vCenter Server
CVE-2023-34048VMware vCenter Server Out-of-Bounds Write Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 22, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)
CVE-2023-20887Vmware Aria Operations for Networks Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 9VMware (Broadcom) Workspace ONE Access / Identity Manager
CVE-2022-22954Ransomware
VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 14, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10VMware (Broadcom) ESXi
CVE-2019-5544RansomwareCVE from 2019, added in 2021
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Show 18 more vulnerabilities
Rank 11VMware (Broadcom) vCenter Server
CVE-2020-3952VMware vCenter Server Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 12VMware (Broadcom) ESXi
CVE-2020-3992Ransomware
VMware ESXi OpenSLP Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 13VMware (Broadcom) vCenter Server
CVE-2021-21972Ransomware
VMware vCenter Server Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 14VMware (Broadcom) vCenter Server
CVE-2021-21985Ransomware
VMware vCenter Server Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 15VMware (Broadcom) vCenter Server
CVE-2021-22005Ransomware
VMware vCenter Server File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 16VMware (Broadcom) Workspace ONE Access / Identity Manager
CVE-2020-4006Multiple VMware Products Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.1 (critical)
Rank 17VMware (Broadcom) ESXi
CVE-2025-22224VMware ESXi and Workstation TOCTOU Race Condition Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.2 (high)
Rank 18VMware (Broadcom) ESXi
CVE-2025-22225Ransomware
VMware ESXi Arbitrary Write Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.2 (high)
Rank 19VMware (Broadcom) SD-WAN (VeloCloud)
CVE-2018-6961CVE from 2018, added in 2022
VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 20VMware (Broadcom) Workspace ONE Access / Identity Manager
CVE-2022-22960VMware Multiple Products Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 15, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
Rank 21VMware (Broadcom) Workstation / Fusion
CVE-2020-3950VMware Multiple Products Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 22VMware (Broadcom) Aria Operations (ex-vRealize Operations)
CVE-2021-21975Ransomware
VMware Server Side Request Forgery in vRealize Operations Manager API
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 23VMware (Broadcom) ESXi
CVE-2024-37085Ransomware
VMware ESXi Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 30, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 24VMware (Broadcom) vCenter Server
CVE-2022-22948CVE from 2022, added in 2024
VMware vCenter Server Incorrect Default File Permissions Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 6.5 (medium)
Rank 25VMware (Broadcom) ESXi
CVE-2025-22226VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 6.0 (medium)
Rank 26VMware (Broadcom) vCenter Server
CVE-2021-21973VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.3 (medium)
Rank 27VMware (Broadcom) vCenter Server
CVE-2021-22017VMware vCenter Server Improper Access Control
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.3 (medium)
Rank 28VMware (Broadcom) VMware Tools
CVE-2023-20867VMware Tools Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 23, 2023
- CISA deadline
- 21 days
- CVSS severity
- 3.9 (low)
Follow and verify
Get new VMware (Broadcom) vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.