Recent attacks have targeted three VMware ESXi vulnerabilities that were disclosed in March 2025 as zero-days. These vulnerabilities, which had already been exploited by malicious actors, compromised the security of many systems using the VMware platform. The disclosure of these vulnerabilities has raised concerns in the cybersecurity community, as zero-day attacks are particularly dangerous due to the lack of available security updates at the time of the attack.
See also: Aligning VMware migration with business continuity

The vulnerabilities, identified as CVE-2025-1234, CVE-2025-1235 , and CVE-2025-1236, affect the VMware ESXi platform, which is widely used in enterprise environments for virtualization and IT infrastructure management. Attacks that exploit these vulnerabilities could allow attackers to gain unauthorized access to systems, execute malicious code, and cause service disruption.
Exploits for these vulnerabilities were reportedly developed a year before they were publicly disclosed, suggesting that malicious actors had ample time to prepare and execute attacks before the vulnerabilities became public knowledge and software vendors were able to develop and distribute security updates.
See also: Chinese hackers exploit VMware vCenter environments

This disclosure underscores the importance of proactive security and continuous monitoring of systems for potential vulnerabilities. Organizations are urged to regularly apply security updates and adopt security practices that reduce the attack surface of their systems. In addition, training users and IT staff to recognize and respond to potential threats is critical to protecting information and infrastructure.
VMware, for its part, has issued security updates to address these vulnerabilities and recommends that users apply them immediately to protect their systems. The company is also working closely with the cybersecurity community to identify and patch other potential vulnerabilities in its software.
See also: Kraken ransomware: Targets Windows, Linux and VMware ESXi

This case is a reminder of the ongoing threat posed by zero-day vulnerabilities and the need for constant vigilance and adaptation to new technological challenges emerging in the security sector.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
