Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

VMware vCenter and NSX Vulnerabilities Let Attackers Enumerate Valid Usernames

VMware has identified significant security vulnerabilities in its vCenter Server and NSX platforms. These vulnerabilities, designated as CVE-2025-41250, CVE-2025-41251, and CVE-2025-41252, are present in various VMware products, including Cloud…

VMware has identified significant security vulnerabilities in its vCenter Server and NSX platforms. These vulnerabilities, designated as CVE-2025-41250, CVE-2025-41251, and CVE-2025-41252, are present in various VMware products, including Cloud Foundation, vSphere Foundation, NSX, NSX-T, and Telco Cloud platforms.

Broadcom, the parent company of VMware, issued a security advisory on Fri, Sep 29, 2025, assessing these vulnerabilities with CVSS base scores from 7.5 to 8.5, categorizing them as "Important."

The National Security Agency (NSA) has reported two of these vulnerabilities due to their potential national security impact.

vCenter SMTP Header Injection Vulnerability

The vulnerability, CVE-2025-41250, is an SMTP header injection issue in VMware vCenter Server with a CVSS score of 8.5. This flaw allows attackers with non-administrative permissions and the ability to create scheduled tasks to alter notification emails sent for those tasks.

The attack requires authenticated access to vCenter with task creation permissions. By leveraging SMTP header injection techniques, attackers can modify email headers, potentially redirecting notifications or inserting malicious content.

This vulnerability affects vCenter Server versions 7.0, 8.0, and 9.x within VMware Cloud Foundation and vSphere Foundation deployments. It also impacts VMware Telco Cloud Platform versions 2.x through 5.x and Telco Cloud Infrastructure versions 2.x and 3.x. No workarounds exist, and security patches should be applied immediately.

VMware has identified significant security vulnerabilities in its vCenter Server and NSX platforms.
Katherine Doyle · Thehackingpost

NSX Username Enumeration Vulnerabilities

Two username enumeration vulnerabilities impact NSX platforms. CVE-2025-41251, with a CVSS score of 8.1, involves a weak password recovery mechanism that allows unauthenticated attackers to enumerate valid usernames. CVE-2025-41252, scoring 7.5, enables attackers to identify valid usernames without authentication.

These vulnerabilities can facilitate reconnaissance attacks, potentially leading to brute-force attacks or credential stuffing campaigns. They affect VMware NSX versions 4.0.x through 4.2.x, NSX-T version 3.x, and NSX components within Cloud Foundation and Telco Cloud platforms.

Security patches are available for NSX 4.2.2.2, 4.2.3.1, 4.1.2.7, and NSX-T 3.2.4.3.

CVE Title CVSS 3.1 Score Severity

CVE-2025-41250 vCenter SMTP Header Injection Vulnerability 8.5 Important

Advertisement

CVE-2025-41251 NSX Weak Password Recovery Mechanism Vulnerability 8.1 Important

CVE-2025-41252 NSX Username Enumeration Vulnerability 7.5 Important

VMware Cloud Foundation users should follow asynchronous patching procedures as outlined in KB88287. Users of Telco Cloud Platform and Infrastructure are advised to refer to KB411518 for update guidance.

The involvement of the NSA in reporting these vulnerabilities highlights their critical importance for enterprise and government environments utilizing VMware infrastructure for virtualization and networking services. Broadcom has released patches that organizations should prioritize to mitigate these vulnerabilities and prevent potential sophisticated attack campaigns.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories