ngCERT[verified]@ngCERTofficialActive Exploitation
CERT-NG warns that CVE-2025-22224 and CVE-2025-22226 in VMware Workstation and Fusion are actively exploited in the wild for VM escape and code execution, urging immediate patching.
ThreatSynop[verified]@ThreatSynopActive Exploitation
CISA confirms ransomware actors are actively exploiting VMware ESXi sandbox‑escape CVE‑2025‑22225, highlighting the urgency of patching unpatched systems, while Huntress notes real‑world chaining with related CVEs.
ThreatSynop[verified]@ThreatSynopActive Exploitation
CISA confirms that VMware ESXi CVE-2025-22225 is actively exploited by ransomware actors using a zero‑day toolkit, with a patch available and urgent patching urged.
ThreatSynop[verified]@ThreatSynopActive Exploitation
CISA reports that ransomware operators are actively exploiting CVE‑2025‑22225 on VMware ESXi hypervisors, using tools such as MAESTRO and VSOCKpuppet to achieve hypervisor takeover and fleet‑wide ransomware deployment.
iototsecnews@iototsecnewsActive Exploitation
VMware ESXi CVE‑2025‑22224/22225/22226 are actively exploited by ransomware, as confirmed by a CISA warning, with detailed information about VM escape and hypervisor memory management flaws.
Alkor Files@AlkorFilesExploit
The post warns that VMware ESXi has a zero‑day (CVE‑2025‑22224/25/26) allowing a VM escape to the hypervisor via a VSOCKpuppet backdoor, potentially affecting 30k+ instances and bypassing network monitoring.
Mockun@Mockun45Active Exploitation
CISA confirms that VMware ESXi vulnerabilities CVE‑2025‑22224/22225/22226 are actively exploited in ransomware attacks.
Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56Patch
Broadcom released a patch for CVE-2025-22225 in March 2025, while the vulnerability and related flaws were acknowledged as actively exploited zero‑days in the wild.