DEV Community

Cyber Updates 365
Cyber Updates 365

Posted on

VMware ESXi Flaw CVE-2025-22225 Now Used in Active Ransomware Attacks

VMware ESXi Flaw CVE-2025-22225 Now Used in Active Ransomware Attacks

CISA warns that the VMware ESXi flaw CVE-2025-22225 is now used in active ransomware attacks. Learn how the sandbox escape works and how to patch it.

The VMware ESXi flaw CVE-2025-22225 is now used in active ransomware attacks, causing massive panic across enterprise data centers. CISA has officially confirmed what many hypervisor administrators feared: this vulnerability, first flagged as a nation-state zero-day, has fully transitioned into the cybercriminal underground.

In February 2026, CISA updated its KEV catalog to mark CVE-2025-22225 as "Known To Be Used in Ransomware Campaigns" — nearly a year after Broadcom initially patched it. The uncomfortable reality is that this exact flaw has quietly existed as an attack chain since at least early 2024. If your ESXi fleet isn't fully patched to the March 2025 fixed builds, you are facing an imminent, non-hypothetical risk of full infrastructure compromise.

Here is the technical detail most panic-driven coverage skips: CVE-2025-22225 cannot be triggered by a random internet-facing attacker with zero foothold. Per Broadcom's own advisory, exploitation requires an attacker to already have administrative privileges inside a guest virtual machine's VMX process. From there, the flaw allows the attacker to trigger an arbitrary kernel write that escapes the VM sandbox and lands them directly on the host hypervisor.

🔗 Read the Full Technical Breakdown, Triple-Threat Vulnerability Chain, and Actionable Patching Checklist on CyberUpdates365

Top comments (0)