Skip to content
English

Products › Brands

Brand

VMware (Broadcom): actively exploited vulnerabilities

28 vulnerabilities in VMware (Broadcom) products (vCenter Server, ESXi, Workspace ONE Access / Identity Manager…) are in CISA’s catalog of exploited vulnerabilities, 1 of them added in the last 90 days. Last added: August 18, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one VMware (Broadcom) category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • vCenter Server 12 vulnerabilities · Virtualization and VDI
  • ESXi 6 vulnerabilities · Virtualization and VDI
  • Workspace ONE Access / Identity Manager 3 vulnerabilities · Identity and access
  • Aria Operations (ex-vRealize Operations) 2 vulnerabilities · Monitoring and ITSM
  • VMware Tools 2 vulnerabilities · Virtualization and VDI
  • Aria Operations for Networks (ex-vRealize Network Insight) 1 vulnerability · Monitoring and ITSM
  • SD-WAN (VeloCloud) 1 vulnerability · Switches and routers
  • Workstation / Fusion 1 vulnerability · Virtualization and VDI

Names used by CISA: Broadcom, VMware. Product families: indicative classification by this site.

Pace of additions

Number of VMware (Broadcom) vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20251
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20260
May 2, 2026 to May 31, 20260
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20261
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this VMware (Broadcom) list.

  1. Rank 1VMware (Broadcom) vCenter Server

    CVE-2026-59310

    Hunt for compromise (CISA)Ransomware

    Broadcom VMware vCenter Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 2VMware (Broadcom) vCenter Server

    CVE-2024-37079

    CVE from 2024, added in 2026

    Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 23, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 3VMware (Broadcom) Aria Operations (ex-vRealize Operations)

    CVE-2026-22719

    Broadcom VMware Aria Operations Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 3, 2026
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  4. Rank 4VMware (Broadcom) VMware Tools

    CVE-2025-41244

    Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 30, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  5. Rank 5VMware (Broadcom) vCenter Server

    CVE-2024-38812

    VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 6VMware (Broadcom) vCenter Server

    CVE-2024-38813

    VMware vCenter Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 20, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 7VMware (Broadcom) vCenter Server

    CVE-2023-34048

    VMware vCenter Server Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 22, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  8. Rank 8VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)

    CVE-2023-20887

    Vmware Aria Operations for Networks Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2022-22954

    Ransomware

    VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 14, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10VMware (Broadcom) ESXi

    CVE-2019-5544

    RansomwareCVE from 2019, added in 2021

    VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
Show 18 more vulnerabilities
  1. Rank 11VMware (Broadcom) vCenter Server

    CVE-2020-3952

    VMware vCenter Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  2. Rank 12VMware (Broadcom) ESXi

    CVE-2020-3992

    Ransomware

    VMware ESXi OpenSLP Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  3. Rank 13VMware (Broadcom) vCenter Server

    CVE-2021-21972

    Ransomware

    VMware vCenter Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  4. Rank 14VMware (Broadcom) vCenter Server

    CVE-2021-21985

    Ransomware

    VMware vCenter Server Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  5. Rank 15VMware (Broadcom) vCenter Server

    CVE-2021-22005

    Ransomware

    VMware vCenter Server File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  6. Rank 16VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2020-4006

    Multiple VMware Products Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.1 (critical)
  7. Rank 17VMware (Broadcom) ESXi

    CVE-2025-22224

    VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  8. Rank 18VMware (Broadcom) ESXi

    CVE-2025-22225

    Ransomware

    VMware ESXi Arbitrary Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  9. Rank 19VMware (Broadcom) SD-WAN (VeloCloud)

    CVE-2018-6961

    CVE from 2018, added in 2022

    VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  10. Rank 20VMware (Broadcom) Workspace ONE Access / Identity Manager

    CVE-2022-22960

    VMware Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  11. Rank 21VMware (Broadcom) Workstation / Fusion

    CVE-2020-3950

    VMware Multiple Products Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  12. Rank 22VMware (Broadcom) Aria Operations (ex-vRealize Operations)

    CVE-2021-21975

    Ransomware

    VMware Server Side Request Forgery in vRealize Operations Manager API

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  13. Rank 23VMware (Broadcom) ESXi

    CVE-2024-37085

    Ransomware

    VMware ESXi Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 30, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  14. Rank 24VMware (Broadcom) vCenter Server

    CVE-2022-22948

    CVE from 2022, added in 2024

    VMware vCenter Server Incorrect Default File Permissions Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  15. Rank 25VMware (Broadcom) ESXi

    CVE-2025-22226

    VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2025
    CISA deadline
    21 days
    CVSS severity
    6.0 (medium)
  16. Rank 26VMware (Broadcom) vCenter Server

    CVE-2021-21973

    VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  17. Rank 27VMware (Broadcom) vCenter Server

    CVE-2021-22017

    VMware vCenter Server Improper Access Control

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    14 days
    CVSS severity
    5.3 (medium)
  18. Rank 28VMware (Broadcom) VMware Tools

    CVE-2023-20867

    VMware Tools Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 23, 2023
    CISA deadline
    21 days
    CVSS severity
    3.9 (low)

Follow and verify

Get new VMware (Broadcom) vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.