Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogransomware-group-operationembedded-device-vulnerability

CISA Flags VMware ESXi CVE-2025-22225 as Exploited in Ransomware Campaigns

Updated 3mo agoFirst seen Feb 5, 20266 sources

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog to indicate that CVE-2025-22225, a high-severity VMware ESXi VMX sandbox escape flaw, is now known to be used in ransomware campaigns. Broadcom patched the issue in March 2025 as part of advisory VMSA-2025-0004, describing CVE-2025-22225 as an arbitrary kernel write reachable by an attacker with privileges in the VMX process, enabling escape from the VMX sandbox to the ESXi kernel. The same advisory also addressed two other zero-days—CVE-2025-22224 (TOCTOU leading to out-of-bounds write/code execution as the VMX process) and CVE-2025-22226 (HGFS out-of-bounds read/memory disclosure)—which Broadcom previously tagged as actively exploited in the wild.

Reporting also tied the ESXi exploitation to earlier sophisticated activity: Huntress described Chinese-speaking threat actors leveraging access via a compromised SonicWall VPN to deliver tooling targeting VMware ESXi and chaining a VM escape technique that appeared to predate public disclosure of the March 2025 ESXi zero-days. Separately, GreyNoise research highlighted a broader KEV-catalog visibility gap, finding that CISA quietly “flipped” dozens of KEV entries during 2025 from “Unknown” to “Known” for ransomware use without prominent public notification—an approach that can materially affect enterprise prioritization when a vulnerability’s status changes to confirmed ransomware exploitation.

Share:
CISA Flags VMware ESXi CVE-2025-22225 as Exploited in Ransomware Campaigns
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 4, 20265mo ago

GreyNoise reveals unpublicized KEV ransomware-flag changes

On February 4, 2026, Dark Reading reported GreyNoise research showing that CISA had made dozens of unannounced KEV ransomware-status updates during 2025. Thorpe also created an RSS feed to alert defenders when KEV ransomware flags change.

Feb 3, 20265mo ago

CISA updates KEV to confirm ransomware exploitation of CVE-2025-22225

On or around February 3, 2026, CISA updated the KEV entry for CVE-2025-22225 to show it is known to be used in ransomware campaigns. CISA did not disclose which ransomware groups or incidents were involved.

Jan 1, 20266mo ago

Huntress publicly reports details of the ESXi exploit toolkit

In January 2026, Huntress disclosed technical findings on an exploit toolkit that likely chained the three VMware ESXi flaws, including use of HGFS, VMCI, kernel-escape shellcode, and a VSOCK-based backdoor. The report linked the tooling to long-term activity by Chinese-speaking exploit developers.

Jul 1, 20251y ago

BlueKeep KEV entry updated to show ransomware use

CISA updated the BlueKeep KEV entry in summer 2025 to indicate known ransomware exploitation, years after the vulnerability's original inclusion. The delayed change was cited by GreyNoise as an example of how KEV ransomware flags can lag real-world risk.

Mar 4, 20251y ago

CISA adds CVE-2025-22225 to the KEV catalog

CISA added CVE-2025-22225 to its Known Exploited Vulnerabilities catalog on March 4, 2025. Under Binding Operational Directive 22-01, U.S. federal agencies were required to remediate the flaw by March 25, 2025.

Mar 1, 20251y ago

Broadcom patches three VMware ESXi zero-days

In early March 2025, Broadcom released VMSA-2025-0004 to patch CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 affecting VMware ESXi. The company said it had indications the flaws had been exploited in the wild as zero-days and warned they could be chained for VM escape and code execution.

Jan 1, 20251y ago

CISA silently flips ransomware-use flags on dozens of KEV entries

During 2025, CISA updated multiple KEV entries to change the field indicating whether a vulnerability was known to be used in ransomware campaigns from "Unknown" to "Known" without public notice. GreyNoise researcher Glenn Thorpe later identified 59 such changes by diffing daily KEV snapshots.

Feb 1, 20242y ago

Chinese-speaking attackers begin covert ESXi exploit-chain activity

Huntress assessed that Chinese-speaking threat actors were likely using a VMware ESXi exploit chain involving CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226 since at least February 2024. Reported activity included use of a compromised SonicWall VPN, an ESXi-focused toolkit, and related persistence and backdoor components.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Malware
1 linked
Affected products
5 linked
Vmware EsxiVmware Vcenter ServerVmware WorkstationVmware Cloud FoundationOracle E-Business Suite
Organizations
17 linked
GreyNoiseBroadcomHuntressBleepingComputerZimbraTom's HardwarePalo Alto NetworksDark ReadingFortinetIvantiMicrosoft CorporationOracleTinesTechTargetAlamyVARBusiness MagazineCRN
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.