Broadcom issued VMSA-2025-0010 to fix four vulnerabilities across VMware ESXi, vCenter Server, Workstation, Fusion, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure, led by CVE-2025-41225, an authenticated command-execution flaw in vCenter Server with a CVSS 8.8 score. According to the advisory, an attacker able to create or modify alarms and run script actions could exploit the bug, while additional fixes address CVE-2025-41226 and CVE-2025-41227 denial-of-service issues and CVE-2025-41228, a reflected XSS flaw affecting ESXi and vCenter Server. VMware said patches are available for all affected products and that no workarounds exist.
The latest advisory follows earlier VMware warnings over serious vCenter Server weaknesses, including VMSA-2024-0012, which disclosed CVE-2024-37079, CVE-2024-37080, and CVE-2024-37081 as memory-management and corruption flaws that could enable remote code execution in vCenter services. VMware said at the time it had no evidence of active exploitation, but urged customers to apply the listed patch versions because no official mitigations were provided; public GitHub material later appeared referencing CVE-2024-37081, underscoring continued security attention on vCenter exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2025-05-20, Broadcom published VMware Security Advisory VMSA-2025-0010 covering four vulnerabilities affecting ESXi, vCenter Server, Workstation, Fusion, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. The most severe, CVE-2025-41225, is an authenticated command-execution flaw in vCenter Server rated CVSS 8.8; updates were released for all affected products and no workarounds were available.
By 2024-07-06, a GitHub repository dedicated to CVE-2024-37081 had been published, indicating public technical material or proof-of-concept activity related to the vCenter Server vulnerability.
On 2024-06-17, VMware published advisory VMSA-2024-0012 for three critical vCenter Server vulnerabilities, CVE-2024-37079, CVE-2024-37080, and CVE-2024-37081. The company said the issues could potentially enable remote code execution, noted ESXi was not affected, and provided patches with no official workaround.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
support.broadcom.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.