CVE-2025-22226Active Exploitation(vmware / cloud_foundation)

MEDIUMCVSS 6.0 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch vmware cloud_foundation systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-125

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • esxi
  • fusion
  • telco_cloud_infrastructure

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cloud_foundationesxifusiontelco_cloud_infrastructuretelco_cloud_platformworkstation

11 versions affected across 6 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-05: 1Mentions · 2026-09-25: 1Active Exploitation · 2026-02-05: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-02-05: 102-0509-25
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ngCERT@ngCERTofficial
    Active Exploitation

    🚨 CRITICAL VMware Workstation & Fusion vulnerabilities (CVE-2025-22224 & CVE-2025-22226) are actively exploited in the wild. Host systems are subject to VM escape & code execution attacks. Patch immediately. Find out more on our website https://cert.gov.ng/advisories/critical-vulnerabilities-in-vmware-workstation-and-fusion #VMware #CyberSecurity #CVE202522224

    Post summary

    The tweet reports that VMware Workstation & Fusion CVEs (CVE-2025-22224 & CVE-2025-22226) are actively exploited in the wild, prompting an immediate patch call. It confirms active in-the-wild exploitation without detailing a specific exploit tool or PoC.

    00000142
    1.4K followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Active Exploitation

    Broadcom patched this ESXi arbitrary-write vulnerability (tracked as CVE-2025-22225) almost one year ago, in March 2025, alongside a memory leak (CVE-2025-22226) and a TOCTOU flaw (CVE-2025-22224), and tagged them all as actively exploited zero-days. https://www.bleepingcomputer.com/news/security/cisa-vmware-esxi-flaw-now-exploited-in-ransomware-attacks/

    Post summary

    Broadcom patched CVE‑2025‑22225 (an ESXi arbitrary‑write flaw) in March 2025, yet the vulnerability – along with related CVEs – is confirmed to be actively exploited, with ransomware attacks reported in the wild.

    00000127
    909 followersView on X
CPE platform detail57 entries

57 of 57 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi7.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
OSvmwareesxi8.0--
Appvmwarefusion---
Appvmwaretelco_cloud_infrastructure2.2--
Appvmwaretelco_cloud_infrastructure2.5--
Appvmwaretelco_cloud_infrastructure2.7--
Appvmwaretelco_cloud_infrastructure3.0--
Appvmwaretelco_cloud_platform2.0--
Appvmwaretelco_cloud_platform2.5--
Appvmwaretelco_cloud_platform2.7--
Appvmwaretelco_cloud_platform3.0--
Appvmwaretelco_cloud_platform4.0--
Appvmwaretelco_cloud_platform4.0.1--
Appvmwaretelco_cloud_platform5.0--
Appvmwareworkstation---

Explore more