
[CIVN-2026-0386] Multiple Vulnerabilities in VMware Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in VMware Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
VMware vCenter Server 8.0 versions prior to 8.0 U3e
VMware vCenter Server 7.0 versions prior to 7.0 U3v
VMware ESXi 8.0 versions prior to ESXi80U3e
VMware ESXi 7.0 versions prior to ESXi70U3v
VMware Workstation Pro 17.x versions prior to 17.6.4
VMware Fusion 13.x versions prior to 13.6.4
VMware Cloud Foundation deployments containing the affected versions of VMware ESXi and VMware vCenter Server
VMware Telco Cloud Platform deployments containing the affected versions of VMware ESXi and VMware vCenter Server
VMware Telco Cloud Infrastructure deployments containing the affected versions of VMware ESXi and VMware vCenter Server
Overview
Multiple vulnerabilities have been reported in VMware products, which could allow an authenticated or local attacker to execute arbitrary code, escalate privileges, perform unauthorized file operations, disclose sensitive information, or cause denial of service on the affected systems.
Target Audience:
All organizations and individuals using the affected VMware products.
Risk Assessment:
High risk of arbitrary code execution, privilege escalation, unauthorized file operations, sensitive information disclosure, and denial of service.
Impact Assessment:
Successful exploitation of these vulnerabilities could allow an authenticated or local attacker to execute arbitrary code, escalate privileges, perform unauthorized file operations, disclose sensitive information, cause denial of service, and compromise the confidentiality, integrity, and availability of the affected systems.
Description
VMware ESXi, VMware vCenter Server, VMware Workstation Pro, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure are virtualization and cloud infrastructure products used to deploy and manage enterprise virtual environments.
These vulnerabilities exist in VMware products due to improper input validation, insufficient validation of user-supplied input, authorization issues, and other implementation flaws in various product components.
Successful exploitation of these vulnerabilities could allow an authenticated or local attacker to execute arbitrary code, escalate privileges, perform unauthorized file operations, disclose sensitive information, cause denial of service, and compromise the confidentiality, integrity, and availability of the affected systems.
Solution
Apply the appropriate security updates as recommended by the vendor.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Vendor Information
Broadcom (VMware)
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
References
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
CVE Name
CVE-2025-41225
CVE-2025-41226
CVE-2025-41227
CVE-2025-41228
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzQwkACgkQ3jCgcSdc
ys8++w//WVaG0uHbT8lKGhP63Mo4Y0dluZVBvocZJZPfzc/ThSa10lqcfeauy7+o
KhWvWEAUwMjXpW+02DsyOxzjGHIwKWeLLCOybfNSlzVgl2w+SBZAgGH8xmVh8W/z
e6G/BozQpEVF/0YAazNF613IGFQ9I9DbDNz1x52x5yIlZAdQN02rdkDxPvP9969n
ncnPjx/eKGiVs2Ux52Hp53h/58J7i/Ob1xF/FH/JeB7oYfzXhopQE1CWIW322RBL
MByMqeoLhbsQaDGwRJbxf6NeDpakN0BmIJ1r5G8Z9TNdx8Uzz1lzvwDsfA41BiZp
Vf6+kqHZ7qxxdhUXpQJVzkKZqew+yqRPvCWxum5gaqiGA96wBNzc34sBr1+UkIlA
CFgYcdKK/4mHlP7H9wnsnG8GeJipZWPjxs+G+kaWxKzBnW8nLvA6B/vyYJEcS12v
sY5l59rgW7GAListpGasRl5xzA+MdSOB7u+pXlkEBueb5FhTVKT7I7/mBneUgA9X
RyPdQzhNkubuVWWWMOas0cRY1mPoCbDnDNgmCXuuQo1y+ywF0Li8UejFQhSjAJMy
/9xuJS6KAUb9JbgDhJ/wceRfHfcgDPKwo4g+T4MJmfLGIjWeVQb3DYuIDRlJX8Nq
MFsvW/yKus4Df4pIPIWHSrhesn+DhdTFOwewHto4/9Fh29hpZPI=
=tb4B
—–END PGP SIGNATURE—–


