The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to indicate that CVE-2025-22225, a high-severity VMware ESXi VMX sandbox escape flaw, is now known to be used in ransomware campaigns. Broadcom patched the issue in March 2025 as part of advisory VMSA-2025-0004, describing CVE-2025-22225 as an arbitrary kernel write reachable by an attacker with privileges in the VMX process, enabling escape from the VMX sandbox to the ESXi kernel. The same advisory also addressed two other zero-days—CVE-2025-22224 (TOCTOU leading to out-of-bounds write/code execution as the VMX process) and CVE-2025-22226 (HGFS out-of-bounds read/memory disclosure)—which Broadcom previously tagged as actively exploited in the wild.
Reporting also tied the ESXi exploitation to earlier sophisticated activity: Huntress described Chinese-speaking threat actors leveraging access via a compromised SonicWall VPN to deliver tooling targeting VMware ESXi and chaining a VM escape technique that appeared to predate public disclosure of the March 2025 ESXi zero-days. Separately, GreyNoise research highlighted a broader KEV-catalog visibility gap, finding that CISA quietly “flipped” dozens of KEV entries during 2025 from “Unknown” to “Known” for ransomware use without prominent public notification—an approach that can materially affect enterprise prioritization when a vulnerability’s status changes to confirmed ransomware exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On February 4, 2026, Dark Reading reported GreyNoise research showing that CISA had made dozens of unannounced KEV ransomware-status updates during 2025. Thorpe also created an RSS feed to alert defenders when KEV ransomware flags change.
On or around February 3, 2026, CISA updated the KEV entry for CVE-2025-22225 to show it is known to be used in ransomware campaigns. CISA did not disclose which ransomware groups or incidents were involved.
In January 2026, Huntress disclosed technical findings on an exploit toolkit that likely chained the three VMware ESXi flaws, including use of HGFS, VMCI, kernel-escape shellcode, and a VSOCK-based backdoor. The report linked the tooling to long-term activity by Chinese-speaking exploit developers.
CISA updated the BlueKeep KEV entry in summer 2025 to indicate known ransomware exploitation, years after the vulnerability's original inclusion. The delayed change was cited by GreyNoise as an example of how KEV ransomware flags can lag real-world risk.
CISA added CVE-2025-22225 to its Known Exploited Vulnerabilities catalog on March 4, 2025. Under Binding Operational Directive 22-01, U.S. federal agencies were required to remediate the flaw by March 25, 2025.
In early March 2025, Broadcom released VMSA-2025-0004 to patch CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 affecting VMware ESXi. The company said it had indications the flaws had been exploited in the wild as zero-days and warned they could be chained for VM escape and code execution.
During 2025, CISA updated multiple KEV entries to change the field indicating whether a vulnerability was known to be used in ransomware campaigns from "Unknown" to "Known" without public notice. GreyNoise researcher Glenn Thorpe later identified 59 such changes by diffing daily KEV snapshots.
Huntress assessed that Chinese-speaking threat actors were likely using a VMware ESXi exploit chain involving CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 since at least February 2024. Reported activity included use of a compromised SonicWall VPN, an ESXi-focused toolkit, and related persistence and backdoor components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.