News

CVE-2025-22225 in VMware ESXi now used in active ransomware attacks

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-02-04 22:02:30 UTC

Ransomware groups now exploit VMware ESXi vulnerability CVE-2025-22225, patched by Broadcom in March 2025. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that ransomware gangs are exploiting the VMware ESXi sandbox escape flaw CVE-2…

CVE-2025-22225 in VMware ESXi now used in active ransomware attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirms that ransomware gangs are exploiting the VMware ESXi san… [+3485 chars]