CVE-2025-22225Active Exploitation(vmware / cloud_foundation)

HIGHCVSS 8.2 · HIGHCISA KEV

Exploitation observed; activity peaked at 23 mentions and remains active

Immediate actions

  • Patch vmware cloud_foundation systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.

7.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787CWE-123

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • esxi
  • telco_cloud_infrastructure
  • telco_cloud_platform

Threat summary

  • Active exploitation appears in 52 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 57 mentions across 11 observed days

What's happening

  • Active exploitation reported across 52 signals
  • Exploit tool or code specified in 3 signals
  • Patch or workaround mentioned in 25 signals
  • Technical details provided in 28 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 9d ago at 23 mentions (2026-02-05); latest day: 2
  • 57 total mentions across 11 days

Affected systems

Vendors
Products
cloud_foundationesxitelco_cloud_infrastructuretelco_cloud_platform

11 versions affected across 4 products

Deep dive

Activity timeline57 mentions / 11d
06121723Mentions · 2026-02-04: 12Mentions · 2026-02-05: 23Mentions · 2026-02-06: 10Mentions · 2026-02-08: 2Mentions · 2026-02-09: 1Mentions · 2026-02-10: 1Mentions · 2026-02-12: 1Mentions · 2026-02-13: 1Mentions · 2026-02-19: 2Mentions · 2026-03-20: 2Mentions · 2026-07-08: 2Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-02-05: 1Exploit Tool / Code · 2026-02-06: 1Active Exploitation · 2026-02-04: 11Active Exploitation · 2026-02-05: 22Active Exploitation · 2026-02-06: 9Active Exploitation · 2026-02-08: 2Active Exploitation · 2026-02-09: 1Active Exploitation · 2026-02-10: 1Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-03-20: 2Active Exploitation · 2026-07-08: 1Patch / Workaround · 2026-02-04: 6Patch / Workaround · 2026-02-05: 10Patch / Workaround · 2026-02-06: 4Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-07-08: 2Technical Details · 2026-02-04: 4Technical Details · 2026-02-05: 12Technical Details · 2026-02-06: 6Technical Details · 2026-02-08: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-13: 1Technical Details · 2026-07-08: 202-0402-0502-0602-0802-0902-1002-1202-1302-1903-2007-08
Signal classification4 categories
Active Exploitation
5291.2%
General
35.3%
Disclosure
11.8%
Patch
11.8%
Referenced assets48 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-0412
Active Exploitation11General1
2026-02-0523
Active Exploitation22General1
2026-02-0610
Active Exploitation9Disclosure1
2026-02-082
Active Exploitation2
2026-02-091
Active Exploitation1
2026-02-101
Active Exploitation1
2026-02-121
Active Exploitation1
2026-02-131
Active Exploitation1
2026-02-192
Active Exploitation1General1
2026-03-202
Active Exploitation2
2026-07-082
Active Exploitation1Patch1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks Source: https://cybersecuritynews.com/vmware-esxi-0-day-ransomware-attack/ CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability. This flaw, patched by Broadcom in March 2025, enables attackers to escape virtual machine isolation and deploy ransomware across hypervisors. CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi, rated Important with a CVSS score of 8.2. A malicious actor with privileges in the VMX process can trigger an arbitrary kernel write, breaking out of the sandbox to gain hypervisor control. #cybersecurityNews #Vulnerability

    Post summary

    CISA confirms active exploitation of CVE-2025-22225, a VMware ESXi sandbox escape flaw, in ransomware attacks, and notes the March 2025 patch from Broadcom.

    9175348212926.6K
    48.2K followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    CVE-2025-22225 https://t.co/OEPZVxatzz

    Post summary

    The tweet cites CVE-2025-22225 with a link but offers no additional context or claims about the vulnerability.

    1001432.0K
    119.7K followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    CISA confirms exploitation of VMware ESXi flaw by ransomware attackers - https://www.helpnetsecurity.com/2026/02/05/cisa-cve-2025-22225-ransomware-exploitation/ - @VMware @GreyNoiseIO #vmware #CyberSecurity #CyberSecurityNews https://t.co/SqIglNUdku

    Post summary

    CISA confirms that VMware ESXi flaw CVE‑2025‑22225 is being actively exploited by ransomware attackers.

    0601101.4K
    60.0K followersView on X
  • hackplayers@hackplayers
    Active Exploitation

    CVE-2025-22225 in VMware ESXi now used in active ransomware attacks https://securityaffairs.com/187637/security/cve-2025-22225-in-vmware-esxi-now-used-in-active-ransomware-attacks.html

    Post summary

    The article reports that CVE-2025-22225 in VMware ESXi is being actively exploited in ransomware attacks.

    03021415
    54.8K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    ⚠️米CISA、VMware ESXiの脆弱性がランサムウェア攻撃に悪用されていると警告(CVE-2025-22225) ✉️中国系ハッカーグループのMustang Panda、偽の外交ブリーフィングで政府関係者をスパイ 〜サイバーアラート2月5日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43780/

    Post summary

    US CISA has warned that VMware ESXi vulnerability CVE-2025-22225 is actively being exploited in ransomware attacks.

    00031378
    1.2K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月4日〜5日のセキュリティ関連ニュース/記事】 <脆弱性> ・米CISA、VMware ESXiの脆弱性がランサムウェア攻撃に悪用されていると警告(CVE-2025-22225) https://www.bleepingcomputer.com/news/security/cisa-vmware-esxi-flaw-now-exploited-in-ransomware-attacks/ ・React2Shellを悪用した攻撃が進行中、クリプトマイナーとリバースシェルを拡散(CVE-2025-55182) https://www.securityweek.com/cryptominers-reverse-shells-dropped-in-recent-react2shell-attacks/ ・Google Lookerに複数の重大な脆弱性、セルフホスト型環境が危険にさらされる(CVE-2025-12743) https://www.helpnetsecurity.com/2026/02/04/google-looker-vulnerabilities-cve-2025-12743/ ・5年前のGitLabの脆弱性が攻撃に悪用される CISAが警告(CVE-2021-39935) https://www.bleepingcomputer.com/news/security/cisa-warns-of-five-year-old-gitlab-flaw-exploited-in-attacks/ ・n8nの重大な脆弱性とエクスプロイトが公開される(CVE-2026-25049) https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/ <マルウェア・その他脅威> ・EDRキラー、EnCaseの署名付きカーネルドライバーを使用してセキュリティを無効化 https://www.bleepingcomputer.com/news/security/edr-killer-tool-uses-signed-kernel-driver-from-forensic-software/ <ランサムウェア> ・ランサムウェアグループ「DragonForce」、カルテルモデル推進で「ゴッドファーザー」さながらに https://www.darkreading.com/cyber-risk/ransomware-gang-full-godfather-cartel ・Nitrogenランサムウェアは実行犯でも復号不可能 身代金支払いは無駄 https://www.theregister.com/2026/02/04/nitrogen_ransomware_broken_decryptor/ <データ侵害/サイバー犯罪> ・大規模な情報漏洩は事実か? メキシコ政府は機微なデータの漏洩を否認 https://www.darkreading.com/cyberattacks-data-breaches/big-breach-or-nada-de-nada-mexican-govt-faces-leak-allegations ・AIを使ったクラウド侵害、公開状態のAWS認証情報から8分で管理者権限を獲得 https://hackread.com/8-minute-takeover-ai-hijack-cloud-access/ ・ShinyHunters、米ハーバード大とペンシルベニア大の内部情報とみられるデータを公開 https://techcrunch.com/2026/02/04/hackers-publish-personal-information-stolen-during-harvard-upenn-data-breaches/ ・ハッカーがnginxサーバーを侵害、ユーザートラフィックをリダイレクト https://www.bleepingcomputer.com/news/security/hackers-compromise-nginx-servers-to-redirect-user-traffic/ <サイバー戦/APT/国家型アクター/地政学関連> ・欧州議会議員、ITサービスの米国依存に警鐘 「EUはマイクロソフトで動いている」 https://www.theregister.com/2026/02/04/eu_foss_fears/ ・ロシアの偵察衛星、EUの複数の通信衛星を傍受 https://arstechnica.com/space/2026/02/russian-spy-satellites-have-intercepted-eu-communications-satellites/ ・米国が2025年にサイバー兵器を攻撃に使用 イランの防空網を混乱させる目的で https://therecord.media/iran-nuclear-cyber-strikes-us ・中国のAmaranth-Dragon、偵察活動でWinRARの脆弱性を悪用(CVE-2025-8088) https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ダークウェブの麻薬市場「Incognito Market」の運営者に拘禁30年の判決 https://www.bleepingcomputer.com/news/security/taiwanese-man-gets-30-years-for-operating-dark-web-drug-market/ <リサーチ/攻撃手法/TTP> ・Windowsのスクリーンセーバーファイル、攻撃者がマルウェアやRMMツールの配布に利用 https://www.darkreading.com/application-security/attackers-use-screensavers-drop-malware-rmm-tools <政府/政策> ・エストニア政府、マイクロソフトへ移行しつつも欧州の代替サービスを模索中 https://www.theregister.com/2026/02/04/estonia_hedges_its_bets_on/ ・米上院議員、ICEデモ参加者に関するデータベースの有無を政府に問う https://arstechnica.com/tech-policy/2026/02/capture-it-all-ice-urged-to-explain-memo-about-collecting-info-on-protesters/ <その他> ・マイクロソフト、Windows 11にネイティブなSysmon機能を導入予定 https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-native-windows-11-sysmon-security-monitoring/

    Post summary

    The text lists multiple CVEs that are currently being actively exploited in the wild, as reported by several security advisories, including VMware ESXi, React2Shell, GitLab, and WinRAR.

    01020353
    1.2K followersView on X
  • Günter Born@etguenni
    Active Exploitation

    BSI-Warnung: 2.500 deutsche VMware ESXi-Server im Internet erreichbar; Angriffe über CVE-2025-22225 https://borncity.com/blog/2026/02/04/cert-bund-warnt-2-500-vmware-esxi-server-im-internet-erreichbar/

    Post summary

    BSI warns that 2,500 German VMware ESXi servers are exposed and are being actively attacked via CVE‑2025‑22225, but no PoC, exploit code, patch, or technical details are disclosed.

    02001319
    2.6K followersView on X
  • cyber_updates_365@CyberUpdates365
    Active Exploitation

    🚨 CRITICAL ALERT: VMware ESXi Sandbox Escape flaw (CVE-2025-22225) lets attackers break out of VMs and take over the host server! 🛑 Threat actors are targeting unpatched hypervisors to deploy enterprise ransomware. Full fix 👇 https://cyberupdates365.com/cve-2025-22225-vmware-esxi-sandbox-escape/ #CyberSecurity #ESXi

    Post summary

    The text alerts that VMware ESXi CVE‑2025‑22225 permits VM escape and host takeover, cites active threat actor targeting, and provides a patch link.

    0002090
    13 followersView on X
  • TrustKernel@PlugMate
    General

    @The_Cyber_News A single ESXi sandbox escape can turn one compromised VM into full hypervisor control. CVE-2025-22225 is a reminder: ransomware has moved up the stack.

    Post summary

    The post highlights CVE‑2025‑22225’s ESXi sandbox escape, noting that a compromised VM could lead to full hypervisor control, but offers no evidence of active exploitation, available patch, or PoC.

    00020647
    15 followersView on X
  • VulnTracker@vuln_tracker
    Active Exploitation

    🚨 Urgent cybersecurity alert: CISA confirms ransomware gangs are now actively exploiting a VMware ESXi 0-day sandbox escape vulnerability (CVE-2025-22225) that lets attackers break out of VMs and control hypervisors — with ransomware deployment now observed in the wild. Patch now! 🔐 Track this CVE and others with precision at https://vulntracker.io/cves/CVE-2025-22225 #infosec #cybersecurity #vmware #CVE #vulnerabilitymanagement #vulnerabilityintelligence

    Post summary

    CISA reports ransomware gangs are actively exploiting CVE-2025-22225, a sandbox escape flaw in VMware ESXi that permits VM escape and hypervisor control, with ransomware deployments observed in the wild. A patch is available immediately.

    00020264
    333 followersView on X
  • Cybersecurity News Alerts@secureblognews
    Patch

    ⚠️ VMware Admins: Running ESXi, Workstation, or Fusion? CVE-2025-22225 is a critical sandbox escape flaw in the USB controller interface. A local VM user can execute arbitrary code on the hypervisor host! Patch & mitigation guide 👇 https://cyberupdates365.com/cve-2025-22225-vmware-esxi-sandbox-escape/ #DevSecOps #BlueTeam

    Post summary

    The tweet alerts VMware administrators to a critical sandbox escape vulnerability (CVE‑2025‑22225) in ESXi, Workstation, and Fusion, providing a link to a patch and mitigation guide.

    0001061
    29 followersView on X
  • Juan Carlos Vázquez @jc_vazquez
    Active Exploitation

    #ICYMI CVE-2025-22225 in VMware ESXi now used in active ransomware attacks. https://securityaffairs.com/187637/security/cve-2025-22225-in-vmware-esxi-now-used-in-active-ransomware-attacks.html

    Post summary

    VMware ESXi vulnerability CVE-2025-22225 is currently being leveraged in ransomware attacks, indicating ongoing active exploitation in the wild.

    00010143
    5.3K followersView on X
  • Rerem Data Security@ReremData
    Active Exploitation

    Ransomware actors are actively exploiting VMware ESXi (CVE-2025-22225). Do you know which of your hypervisors are internet-exposed right now? Audit access, remove direct exposure, and patch immediately. #CyberSecurity #Ransomware https://t.co/Us3k0DCoAA

    Post summary

    The tweet reports that ransomware actors are actively exploiting VMware ESXi CVE-2025-22225 and urges immediate patching of exposed hypervisors.

    1000046
    30 followersView on X
  • Fourtrezz@fourtrezz_
    General

    [Cyber Bulletin Fourtrezz] Kabar Seputar Teknologi dan Keamanan Siber Baca berita terkini melalui link, https://fourtrezz.co.id/celah-v-mware-es-xi-cve-2025-22225-jadi-senjata-ransomware-toolkit-cina-terdeteksi-sejak-2024/ #keamanansiber #beritaterkini #cybersecurity #cyberbulletin #CybersecurityNews #cybersecurityawareness #teknologi #cybersecuritynews #daretosafe

    Post summary

    The content merely links to an article announcing CVE‑2025‑22225 in VMware ESXi, offering no technical details, PoC, or exploitation evidence.

    1000072
    4 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    VMware ESXi の脆弱性 CVE-2025-22224/22225/22226:ランサムウェアによる悪用を CISA が確認 https://iototsecnews.jp/2026/02/05/cisa-warns-of-vmware-esxi-0-day-vulnerability-exploited-in-ransomware-attacks/ VMware ESXi における深刻な脆弱性が、ランサムウェア攻撃で悪用されていると、CISA が警告を出しています。この問題の原因は、ハイパーバイザのメモリ管理に関する設計上の不備にあります。具体的には、脆弱性 CVE-2025-22225 を悪用することで、仮想マシンのサンドボックスを突破し、管理下の全システムを制御するハイパーバイザへ直接アクセスできてしまう “VMエスケープ” が可能になってしまいます。この不備に加えて、管理者権限の不適切な運用や、CVE-2025-22224 などの複数の欠陥を組み合わせる攻撃手法により、本来守られるべき仮想マシン同士の境界が無効化されます。現在も、パッチ未適用のシステムが存在し、この攻撃の潜在的な標的にされていると、CISA は注意を促しています。 #CISA #CVE202522224 #CVE202522225 #CVE202522226 #ESXi #Exploit #Government #KEV #VMware #Vulnerability

    Post summary

    CISA confirmed that VMware ESXi vulnerabilities CVE‑2025‑22224/25/26 are actively exploited in ransomware attacks, enabling VM escape through hypervisor memory‑management flaws and compromising unpatched systems.

    01000192
    483 followersView on X
  • ProbablyPwned@probablypwned
    Active Exploitation

    CVE-2025-22225 sandbox escape confirmed as ransomware attack vector. Exploitation toolkit predates Broadcom's patch by a full year. Read more: https://www.probablypwned.com/article/vmware-esxi-cve-2025-22225-ransomware-cisa-confirms

    Post summary

    CVE-2025-22225 is actively exploited as a ransomware vector, with a known exploit toolkit existing a year before the Broadcom patch, confirming real-world attacks.

    1000063
    16 followersView on X
  • Dr.Philippe Vynckier, CISSP - Influencer@PVynckier
    Active Exploitation

    CISA confirms exploitation of VMware ESXi flaw by ransomware attackers - Help Net Security https://www.helpnetsecurity.com/2026/02/05/cisa-cve-2025-22225-ransomware-exploitation/

    Post summary

    CISA confirms that the VMware ESXi flaw (CVE-2025-22225) is being actively exploited by ransomware attackers.

    0001092
    24.1K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CISA confirms exploitation of VMware ESXi flaw by ransomware attackers https://www.helpnetsecurity.com/2026/02/05/cisa-cve-2025-22225-ransomware-exploitation/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA reports that ransomware actors are exploiting the VMware ESXi CVE‑2025‑22225 vulnerability in the wild.

    00010482
    192.8K followersView on X
  • Shah Sheikh@shah_sheikh
    Active Exploitation

    CVE-2025-22225 in VMware ESXi now used in active ransomware attacks: Ransomware groups now exploit VMware ESXi vulnerability CVE-2025-22225, patched by Broadcom in March 2025. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that… https://securityaffairs.com/187637/security/cve-2025-22225-in-vmware-esxi-now-used-in-active-ransomware-attacks.html?utm_source=dlvr.it&utm_medium=twitter https://t.co/MVTTNBKCSn

    Post summary

    CVE-2025-22225 in VMware ESXi is actively being exploited by ransomware groups, confirmed by CISA, and has been patched by Broadcom in March 2025.

    0100067
    2.2K followersView on X
  • Eric Vanderburg@evanderburg
    Active Exploitation

    CVE-2025-22225 in VMware ESXi now used in active ransomware attacks http://i.securitythinkingcap.com/TQmFYX #BreakingNews https://t.co/QzkwJghHxv

    Post summary

    CVE-2025-22225 in VMware ESXi is being actively exploited in ransomware attacks.

    01000115
    44.1K followersView on X
CPE platform detail55 entries

55 of 55 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
Appvmwaretelco_cloud_infrastructure2.2--
Appvmwaretelco_cloud_infrastructure2.5--
Appvmwaretelco_cloud_infrastructure2.7--
Appvmwaretelco_cloud_infrastructure3.0--
Appvmwaretelco_cloud_platform2.0--
Appvmwaretelco_cloud_platform2.5--
Appvmwaretelco_cloud_platform2.7--
Appvmwaretelco_cloud_platform3.0--
Appvmwaretelco_cloud_platform4.0--
Appvmwaretelco_cloud_platform4.0.1--
Appvmwaretelco_cloud_platform5.0--

Explore more