Skip to content
VulniPulse

VMware (Broadcom) Security Advisories & CVEs

71 advisories tracked · VMware Security Advisories (VMSA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor VMware CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your VMware device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in VMware's recent advisories.

Official source

VMware Security Advisories (VMSA) via NVD

Broadcom's VMSA portal is a JavaScript app with no stable public feed, so VulniPulse ingests VMware CVEs from NVD filtered to VMware's own CNAs (security@vmware.com and Broadcom's successor CNA) — official, CNA-published data covering ESXi, vCenter Server, NSX, Aria/vRealize, Cloud Foundation, Workstation/Fusion and VMware Tools. Each entry links back to the Broadcom/VMware advisory when NVD carries the reference.

Latest VMware advisories

Medium4.8VMware

Medium [CVE-2026-22751] Spring Security: Vulnerability in Spring Spring Security.

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.

CVE-2026-22751
Tanzu / Spring
Apr 21, 2026
Medium5.9VMware

Medium [CVE-2026-22737] Spring Framework: Use of Java scripting engine enabled (e.g.

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVE-2026-22737
Tanzu / Spring
Mar 20, 2026
Medium6.5VMware

Medium [CVE-2026-22723] Inappropriate user token revocation

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.

CVE-2026-22723
Unclassified
Mar 5, 2026
Medium5.0VMware

Medium [CVE-2026-22716] Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform

Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to terminate certain Workstation processes.

CVE-2026-22716
Workstation & Fusion
Feb 27, 2026
Medium6.1VMware

Medium [CVE-2026-22722] malicious actor with authenticated user privileges on a Windows based Workstation host

A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

CVE-2026-22722
Workstation & Fusion
Feb 26, 2026
Medium5.9VMware

Medium [CVE-2026-22715] Workstation: VMWare Workstation and Fusion contain a logic flaw in the management of network packets.

VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's. Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 25H2U1

CVE-2026-22715
Workstation & Fusion
Feb 26, 2026
Medium4.9VMware

Medium [CVE-2026-22728] Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow.

Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrusted spec.template.metadata.annotations present in the input SealedSecret. By submitting a victim SealedSecret to the rotate endpoint with the annotation sealedsecrets.bitnami.com/cluster-wide=true injected into the template metadata, a remote attacker can obtain a rotated version of the secret that is cluster-wide. This bypasses original "strict" or "namespace-wide" constraints, allowing the attacker to retarget and unseal the secret in any namespace or under any name to recover the plaintext credentials.

CVE-2026-22728
Unclassified
Feb 26, 2026
Medium6.2VMware

Medium [CVE-2026-22721] vCenter: VMware Aria Operations contains a privilege escalation vulnerability.

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMSA-2026-0001.

CVE-2026-22721
vCenterAria / vRealize
Feb 25, 2026
Medium6.2VMware

Medium [CVE-2025-62349] Salt contains an authentication protocol version downgrade weakness that can

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

CVE-2025-62349
Unclassified
Jan 30, 2026
Medium5.3VMware

Medium [CVE-2025-22228 +1] The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

CVE-2025-22228CVE-2025-22234
Unclassified
Jan 22, 2026
Medium6.8VMware

Medium [CVE-2026-22718] The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine

The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

CVE-2026-22718
Unclassified
Jan 14, 2026

← All vendors