Quick Summary
The Securityish Brief
CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to confirm that the VMware ESXi arbitrary write vulnerability, CVE-2025-22225, is being actively exploited in ransomware campaigns. This vulnerability, along with CVE-2025-22224, a heap overflow flaw, and CVE-2025-22226, an information disclosure issue, were addressed by Broadcom in early March 2025. At that time, Broadcom indicated that these vulnerabilities had been exploited as zero-days, although specific attack details were not disclosed.
In January 2026, Huntress researchers identified an exploit toolkit believed to leverage all three vulnerabilities. Their analysis suggested that the toolkit utilizes HGFS for information leakage, VMCI for memory corruption, and kernel-escaping shellcode. The researchers noted that evidence indicated the toolkit may have been developed by Chinese-speaking exploit developers prior to VMware’s public disclosure.
Currently, while CVE-2025-22225 is flagged as ‘Known To Be Used in Ransomware Campaigns,’ the statuses of CVE-2025-22224 and CVE-2025-22226 remain ‘Unknown.’ This discrepancy complicates patch prioritization for private-sector organizations, which are more vulnerable to ransomware attacks compared to nation-state cyber-espionage.
Experts have pointed out that relying on the KEV catalog for prioritization can be a lagging indicator, and waiting for ransomware flags can slow down response efforts. Greater transparency from CISA regarding updates to the knownRansomwareCampaignUse field would be beneficial for organizations.
As a workaround, Glenn Thorpe from GreyNoise has suggested using an RSS feed that checks the KEV catalog hourly, alerting subscribers whenever CISA updates the ransomware status of vulnerabilities.
Key Takeaways
- Regularly check for updates on CVE-2025-22225 and related vulnerabilities to stay informed about potential risks.
- Implement the latest patches from Broadcom for VMware ESXi, Workstation, and Fusion to mitigate exploitation risks.
- Consider using the RSS feed recommended by GreyNoise to receive timely alerts about updates to the KEV catalog.
- Evaluate your organization’s vulnerability management strategy to ensure timely patching of known vulnerabilities.
- Stay vigilant against ransomware threats by monitoring network activity and employing robust security measures.
Key Terms & Concepts
- CVE-2025-22225: In this article, CVE-2025-22225 refers to a VMware ESXi arbitrary write vulnerability exploited in ransomware campaigns.
- CISA: CISA stands for the Cybersecurity and Infrastructure Security Agency, which manages the KEV catalog for known vulnerabilities.
- KEV catalog: The KEV catalog is a list maintained by CISA that identifies vulnerabilities that federal agencies must remediate.
- zero-day: A zero-day refers to a vulnerability that is exploited before the vendor has issued a fix.
- exploit toolkit: An exploit toolkit is a collection of software tools used by attackers to exploit vulnerabilities in systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.