Broadcom addressed three high-severity vulnerabilities in VMware products following notification from the National Security Agency (NSA), highlighting the potential national security implications of these flaws. The vulnerabilities, identified as CVE-2025-41250 affecting vCenter Server and CVE-2025-41251 and CVE-2025-41252 affecting VMware NSX, impact a range of VMware products including NSX, NSX-T, VMware Cloud Foundation, VMware vCenter Server, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Security professionals noted that the NSA's involvement suggests a heightened risk of exploitation by nation-state actors, referencing previous incidents where Russian state-sponsored groups targeted VMware vulnerabilities. The two NSX vulnerabilities allow unauthenticated attackers to enumerate valid usernames on affected systems, which can be leveraged in combination with weak or reused credentials to facilitate deeper network penetration. The vCenter Server vulnerability involves SMTP header injection, which could be used in further attack chains. While there is no public evidence that these specific vulnerabilities have been exploited in the wild, experts warn that their combination could enable attackers to progress from reconnaissance to authenticated compromise. The vulnerabilities were disclosed and patched on September 29, 2025, with Broadcom urging customers to apply updates promptly. In parallel, security researchers at NCC Group have published detailed technical analyses of guest-to-host escape vulnerabilities in VMware Workstation, demonstrating how attackers can exploit information leaks and stack-based buffer overflows to execute code on the host operating system from a compromised guest VM. The research includes proof-of-concept exploit development using tools such as Ghidra and WinDBG, providing valuable insights for red teamers and penetration testers. These findings underscore the ongoing risks associated with virtualization platforms, where vulnerabilities can enable attackers to break out of isolated environments and compromise underlying infrastructure. The technical depth of the NCC Group's research highlights the complexity of exploit development for VMware products and the importance of robust vulnerability management. The combination of newly patched vulnerabilities and active exploit research emphasizes the need for organizations to maintain up-to-date security controls and monitor for signs of suspicious activity in virtualized environments. Security teams are advised to review VMware advisories, apply patches without delay, and consider additional hardening measures for critical systems. The involvement of intelligence agencies in vulnerability disclosure further illustrates the strategic importance of securing virtualization technologies in both enterprise and government contexts. Organizations should also be aware of the potential for these vulnerabilities to be used in targeted attacks, particularly by sophisticated threat actors. Ongoing collaboration between vendors, security researchers, and government agencies remains essential to address emerging threats in the virtualization space.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On Sept. 29, 2025, Broadcom issued fixes for the three reported VMware vulnerabilities. The patched flaws included an SMTP header injection issue in vCenter Server and two NSX/NSX-T issues that could allow unauthenticated username enumeration.
Broadcom said the U.S. National Security Agency notified it of three high-severity flaws affecting VMware vCenter Server and VMware NSX/NSX-T. The issues were tracked as CVE-2025-41250, CVE-2025-41251, and CVE-2025-41252.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.