Skip to content
VulniPulse

VMware (Broadcom) Cloud Foundation Vulnerabilities & Security Advisories

9 advisories tracked · VMware Security Advisories (VMSA) via NVD · 4 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published VMware (Broadcom) advisory that VulniPulse classified as Cloud Foundation, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 3 critical, 3 high, 1 low.

Android app · Google Play

Monitor VMware CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

VMware Security Advisories (VMSA) via NVD

Broadcom's VMSA portal is a JavaScript app with no stable public feed, so VulniPulse ingests VMware CVEs from NVD filtered to VMware's own CNAs (security@vmware.com and Broadcom's successor CNA) — official, CNA-published data covering ESXi, vCenter Server, NSX, Aria/vRealize, Cloud Foundation, Workstation/Fusion and VMware Tools. Each entry links back to the Broadcom/VMware advisory when NVD carries the reference.

Latest VMware Cloud Foundation advisories

High7.6VMware

High [CVE-2026-41703] Out-of-bounds read vulnerability

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41703
ESXiCloud FoundationWorkstation & FusionvSphere
Jul 30, 2026
High8.0VMware

High [CVE-2026-41724] VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with…

VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations.

CVE-2026-41724
Cloud Foundation
Jun 8, 2026
High8.2VMware Exploited CISA KEV

High [CVE-2025-22225] VMware ESXi contains an arbitrary write vulnerability

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. Affected products named by the advisory: VMware Cloud Foundation; VMware Telco Cloud Platform; VMware Telco Cloud Infrastructure.

CVE-2025-22225
ESXiCloud Foundation
Mar 4, 2025

← All VMware advisories