VMware ESXi vulnerabilities expose organizations to heightened cyber risks now

VMware ESXi vulnerabilities expose organizations to heightened cyber risks now

In December 2025, a sophisticated cyberattack leveraging three critical VMware vulnerabilities, with CVSS scores up to 9.3, was thwarted, potentially preventing a major ransomware crisis.

NeboAI I summarize the news with data, figures and context
IN 30 SECONDS

IN 1 SENTENCE

SENTIMENT
Neutral

𒀭
NeboAI is working, please wait...
Preparing detailed analysis
Quick summary completed
Extracting data, figures and quotes...
Identifying key players and context
DETAILED ANALYSIS
SHARE

NeboAI produces automated editions of journalistic texts in the form of summaries and analyses. Its experimental results are based on artificial intelligence. As an AI edition, texts may occasionally contain errors, omissions, incorrect data relationships and other unforeseen inaccuracies. We recommend verifying the content.

A cybersecurity incident involving Chinese-speaking threat actors has been linked to a compromised SonicWall VPN appliance, which served as a gateway for deploying a VMware ESXi exploit. This activity, observed by Huntress in December 2025, was halted before it could escalate into a ransomware attack.

Three significant vulnerabilities were exploited during this incident, specifically CVE-2025-22224 (CVSS score: 9.3), CVE-2025-22225 (CVSS score: 8.2), and CVE-2025-22226 (CVSS score: 7.1). These were publicly disclosed by Broadcom in March 2025 and subsequently added to the Known Exploited Vulnerabilities catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Research indicates that the toolkit utilized in the attack was likely developed over a year before the public disclosure of the vulnerabilities. It features several components, including "exploit.exe," which orchestrates the virtual machine escape. The exploit's design suggests a sophisticated developer group, potentially operating from a Chinese-speaking region, with evidence of Chinese language strings present in the toolkit's paths.

Want to read the full article? Access the original article with all the details.
Read Original Article
TL;DR

This article is an original summary for informational purposes. Image credits and full coverage at the original source. · View Content Policy

Editorial
Editorial Staff

Our editorial team works around the clock to bring you the latest tech news, trends, and insights from the industry. We cover everything from artificial intelligence breakthroughs to startup funding rounds, gadget launches, and cybersecurity threats. Our mission is to keep you informed with accurate, timely, and relevant technology coverage.

Press Enter to search or ESC to close