Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CISA Warns of VMware ESXi 0-day Vulnerability Exploited in Ransomware Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has verified that ransomware groups are currently exploiting CVE-2025-22225, a significant VMware ESXi sandbox escape vulnerability.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has verified that ransomware groups are currently exploiting CVE-2025-22225, a significant VMware ESXi sandbox escape vulnerability.

This vulnerability, addressed by Broadcom in March 2025, allows attackers to bypass virtual machine isolation, facilitating ransomware deployment across hypervisors.

CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi, with an Important rating and a CVSS score of 8.2. Exploitation allows malicious actors with VMX process privileges to initiate an arbitrary kernel write, leading to hypervisor control.

It was disclosed alongside two other zero-days, CVE-2025-22224 (CVSS 9.3, heap overflow) and CVE-2025-22226 (CVSS 7.1, information disclosure), all of which have been exploited since early 2025.

CVE ID CVSS Score Description Affected Products

CVE-2025-22224 9.3 Heap overflow in VMCI driver ESXi 7.0, 8.0; Workstation 17.0

CVE-2025-22225 is an arbitrary write vulnerability in VMware ESXi, with an Important rating and a CVSS score of 8.2.
Julia Kramer · Thehackingpost

CVE-2025-22225 8.2 Arbitrary kernel write via VMX ESXi 7.0, 8.0

CVE-2025-22226 7.1 HGFS memory leak ESXi, Workstation, Fusion

CISA added CVE-2025-22225 to its Known Exploited Vulnerabilities (KEV) catalog on March 4, 2025, requiring federal patches by March 25 under BOD 22-01.

Recent updates on February 3, 2026, have highlighted its use in ransomware campaigns, although details on specific groups have not been disclosed. Attackers combine this with other vulnerabilities for complete VM escape, targeting enterprise hypervisors managing sensitive data.

Ransomware actors often gain initial VM access through administrative privileges, disabling VMCI drivers, loading unsigned kernel drivers, and leaking VMX memory to bypass ASLR.

Advertisement

This behavior facilitates the deployment of backdoors such as VSOCKpuppet for sustained hypervisor control while avoiding network detection. Previous exploitation by Chinese-linked hackers began in February 2024 via compromised SonicWall VPNs, leading to data exfiltration and ransomware preparation.

Broadcom's VMSA-2025-0004 advisory confirmed active exploitation at the time of the patch release. Scans indicate over 41,500 exposed ESXi instances remain vulnerable, increasing the risk of ransomware attacks. A toolkit targeting 155 ESXi builds was reported by Huntress, with development traces dating over a year prior.

It is imperative to apply Broadcom patches immediately for ESXi 7.0/8.0 and related products. CISA advises following vendor mitigations, implementing BOD 22-01 for cloud environments, or discontinuing systems that cannot be patched. Enhancing defenses with EDR monitoring for VMX anomalies, restricting VM administrative privileges, and scanning for indicators of compromise such as unsigned drivers or VSOCK traffic is also recommended.

Given the widespread use of VMware ESXi in enterprises, it remains a primary target for ransomware attacks. Organizations should prioritize patching hypervisors amidst increasing state-sponsored and cybercrime threats. Unpatched systems risk comprehensive infrastructure encryption and data breaches.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories