U.S. CISA adds Linux kernel and VMware ESXi and Workstation flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 5, 06:09 UTC · Mar 5, 2025Exploit / PoC in the wildCVE-2024-50302CVE-2025-22225CVE-2025-22224+3 CVEs60
+20,000 internet-exposed VMware ESXi instances vulnerable to CVE-2024Security Affairs·Aug 1, 20:28 UTC · Aug 1, 2024Ransomware in the wildCVE-2024-3708560
CVE-2025-22225 in VMware ESXi now used in active ransomware attacksSecurity Affairs·Feb 4, 22:02 UTC · Feb 4, 2026Ransomware in the wildCVE-2025-22225CVE-2025-22226CVE-2025-2222460
Zeodium pays up to $500,000 for VMware ESXi, Microsoft HyperSecurity Affairs·Mar 8, 09:09 UTC · Mar 8, 2019Exploit / PoC60
China-linked APT UNC3886 used VMware ESXi ZeroSecurity Affairs·Jun 14, 08:44 UTC · Jun 14, 2023Exploit / PoCCVE-2023-2086760
BlackByte Ransomware group targets recently patched VMware ESXi flaw CVE-2024Security Affairs·Aug 28, 14:39 UTC · Aug 28, 2024RansomwareCVE-2024-3708560
BlackMatter ransomware also targets VMware ESXi serversSecurity Affairs·Aug 6, 06:53 UTC · Aug 6, 2021Ransomware60
CISA confirms exploitation of VMware ESXi flaw by ransomware attackersHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2026Ransomware in the wildCVE-2025-22225CVE-2025-22224CVE-2025-2222660
Ransomware gang uses a Python script to encrypt VMware ESXi serversSecurity Affairs·Oct 5, 16:13 UTC · Oct 5, 2021Ransomware160
VMware ESXi auth bypass zero-day exploited by ransomware operators (CVE-2024-37085)Help Net Security·Jul 30, 00:00 UTC · Jul 30, 2024Ransomware in the wildCVE-2024-3708560
VMware ESXi Flaw Exploited by Ransomware Groups for Admin AccessThe Hacker News·Jul 31, 04:04 UTC · Jul 31, 2024Ransomware in the wildCVE-2024-37085CVE-2023-28252160
Play Ransomware Expands to Target VMWare ESXi EnvironmentsInfosecurity Magazine·Jul 22, 17:15 UTC · Jul 22, 2024Ransomware60
BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack WaveThe Hacker News·Aug 29, 15:41 UTC · Aug 29, 2024RansomwareCVE-2024-3708560
Pwn2Own Berlin 2025 Day Two: researcher earned 150K hacking VMware ESXiSecurity Affairs·May 16, 20:11 UTC · May 16, 2025Exploit / PoC60
Week in review: VMware ESXi servers under attack, ChatGPT’s malicious potential, Reddit breachedHelp Net Security·Feb 12, 00:00 UTC · Feb 12, 2023Data breachCVE-2021-2197460
Week in review: VMware ESXi zero-day exploited, SMS Stealer malware targeting Android usersHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2024Exploit / PoC in the wildCVE-2023-45249CVE-2024-3708560
VMware patches critical flaws in ESXi, Workstation, Fusion and Cloud FoundationHelp Net Security·Mar 7, 00:00 UTC · Mar 7, 2024VulnerabilityCVE-2024-22252CVE-2024-22253CVE-2024-22254+1 CVEs60
Threat Analysis: VMware ESXi Attacks Soared in 2022Infosecurity Magazine·Feb 15, 12:00 UTC · Feb 15, 2023RansomwareCVE-2021-2197460
Critical RCE Flaws Affect VMware ESXi and vSphere Client — Patch NowThe Hacker News·Feb 24, 17:35 UTC · Feb 24, 2021Vulnerability in the wildCVE-2021-21972CVE-2019-19781CVE-2021-21973+3 CVEs60
Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. InfrastructureThe Hacker News·Jul 29, 04:19 UTC · Jul 29, 2025Ransomware60
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
New Linux Variant of Play Ransomware Targeting VMware ESXi SystemsThe Hacker News·Jul 22, 05:48 UTC · Jul 22, 2024Ransomware60
US CISA releases a script to recover servers infected with ESXiArgs ransomwareSecurity Affairs·Feb 8, 09:45 UTC · Feb 8, 2023RansomwareCVE-2021-2197460
VMware has no evidence of zero-day exploitation in ESXiArgs ransomware attacksSecurity Affairs·Feb 7, 15:52 UTC · Feb 7, 2023RansomwareCVE-2021-2197460
VMware fixed three actively exploited zeroSecurity Affairs·Mar 4, 23:39 UTC · Mar 4, 2025Exploit / PoC in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
VMware fixes flaws demonstrated at Chinese Tianfu Cup hacking contestSecurity Affairs·Feb 16, 09:15 UTC · Feb 16, 2022Exploit / PoCCVE-2021-22040CVE-2021-22041CVE-2021-22042+1 CVEs60
VMware addresses flaws exploited at recent Tianfu CupSecurity Affairs·Nov 20, 21:12 UTC · Nov 20, 2020VulnerabilityCVE-2020-4004CVE-2020-400560
New variant of ESXiArgs ransomware makes recovery much harderSecurity Affairs·Feb 9, 17:08 UTC · Feb 9, 2023RansomwareCVE-2021-2197460
VMware Warns Customers to Patch Actively Exploited ZeroInfosecurity Magazine·Mar 4, 15:45 UTC · Mar 4, 2025Vulnerability in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
VMware addresses ESXi issue disclosed at the Tianfu Cup competitionSecurity Affairs·Dec 6, 13:07 UTC · Dec 6, 2019Exploit / PoCCVE-2019-554460
VMware urgent updates addressed Critical ESXi Sandbox Escape bugsSecurity Affairs·Mar 5, 21:47 UTC · Mar 5, 2024VulnerabilityCVE-2024-22252CVE-2024-22253CVE-2024-22254+1 CVEs60
VMware Security Flaws Exploited in the Wild—Broadcom Releases Urgent PatchesThe Hacker News·Jan 9, 17:29 UTC · Jan 9, 2026Exploit / PoC in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
Broadcom Patches Critical ESXi Vulnerability Enabling Host Code ExecutionSecurity Affairs·Jul 29, 13:02 UTC · Jul 29, 2026Vulnerability in the wildCVE-2026-47876CVE-2026-59309CVE-2026-59310+2 CVEs60
Chinese-speaking hackers exploited ESXi zeroSecurity Affairs·Jan 9, 00:06 UTC · Jan 9, 2026Ransomware in the wildCVE-2025-22226CVE-2025-22224CVE-2025-2222560
Fire Ant Exploits VMware Flaws to Compromise ESXi Hosts and vCenter EnvironmentsThe Hacker News·Jul 29, 04:24 UTC · Jul 29, 2025Exploit / PoCCVE-2023-34048CVE-2023-20867CVE-2022-138860
Italy, France and Singapore Warn of a Spike in ESXI RansomwareSecurity Affairs·Feb 6, 21:55 UTC · Feb 6, 2023RansomwareCVE-2021-2197460
VMware fixes several flaws in its ESXi, Workstation, Fusion and NSX-TSecurity Affairs·Oct 22, 07:26 UTC · Oct 22, 2020VulnerabilityCVE-2020-3992CVE-2020-3993CVE-2020-399460
BlackByte Adopts New Tactics, Targets ESXi HypervisorsInfosecurity Magazine·Aug 29, 16:30 UTC · Aug 29, 2024RansomwareCVE-2024-3708560
CISA adds VMware vCenter Server bug to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 23, 08:00 UTC · Jan 23, 2024Exploit / PoC in the wildCVE-2023-34048CVE-2023-20867160
China-linked APT UNC3886 exploits VMware zeroSecurity Affairs·Jan 22, 22:57 UTC · Jan 22, 2024Exploit / PoCCVE-2023-34048CVE-2023-20867260