Broadcom released VMware vSphere 8.0 Update 3k on 29 July 2026, delivering critical security fixes for both vCenter Server and ESXi. Normally, the recommendation would be straightforward: review the release notes, validate the patch in a test environment, and deploy it as quickly as your change-management process allows. This release, however, comes with an important…
Read moreCategory: Security Advisory
VMware Aria Hit With RCE Bugs. Yes, You Should Care.
If you’re running VMware Aria Operations, VMware Aria Automation, or any part of the Aria stack in production, stop scrolling. On February 24, 2026, Broadcom released VMSA-2026-0001, disclosing three vulnerabilities in VMware Aria Operations. They’re all rated Important. One of them enables remote code execution. If Aria Operations is part of your control plane, this…
Read morevCenter Server CVE-2024-37079 Is Now Getting Weaponized in Ransomware Campaigns (Patch Like You Mean It)
f your vCenter patching has been sitting in the “next maintenance window” pile since 2024… that window just closed. VMware by Broadcom has confirmed in-the-wild exploitation of CVE-2024-37079 in VMware vCenter Server, and CISA has flagged it as actively exploited with a hard remediation deadline for U.S. federal agencies of February 13, 2026. That combination…
Read morevCenter Is the Crown Jewel: What “Exploitation in the Wild” Really Means for VMware Admins
Before you read : TL;DR: Broadcom confirmed active exploitation of critical VMware vCenter Server vulnerabilities (CVE-2024-38812 / CVE-2024-38813). Separately, threat intel reporting shows China-nexus operators targeting vCenter environments and deploying web shells/backdoors for persistence. If vCenter is reachable from untrusted networks—or you’re slow to patch—assume you’re playing defense on hard mode Why this matters (and…
Read moreHow Anyone Could Hijack Your Flowise Account — Without Knowing Your Password
What is Flowise? Flowise is an open-source platform for building AI-powered applications such as chatbots and agent systems. It provides a visual drag-and-drop interface that makes it possible to design workflows without writing extensive code. Under the hood, it supports large language models (LLMs), Retrieval-Augmented Generation (RAG), and integrates with multiple data sources. Developers can…
Read moreVMware Security Advisory: VMSA-2025-0013 – Critical Vulnerabilities in VMware Products
Affected Products: Introduction VMware Security Team has released VMSA-2025-0013, addressing several critical vulnerabilities across a range of VMware products. These vulnerabilities could potentially lead to code execution, information disclosure, or other severe security risks if left unpatched. The vulnerabilities were privately reported and patches are now available to remediate the issues. Vulnerabilities Overview The vulnerabilities…
Read moreMajor Change Alert: VMware Patch Downloads Now Require Tokens
Broadcom has rolled out a significant change that affects all VMware patching workflows: shared public patch URLs are no longer supported. From now on, every environment must use per-customer download tokens for accessing software depots across ESXi, vCenter, VAMI, and Cloud Foundation components. Let’s break down what’s happening, why it matters, and how to fix…
Read moreCybersecurity Wake-Up Call: RVTools Users Targeted in Shocking Malware Campaign – What every VMware admin needs to know right now!
If you’re a systems engineer, VMware admin, or IT pro who swears by RVTools, this one’s going to hit hard: the official RVTools websites — long considered the trusted home for the popular VMware inventory reporting tool — have recently become ground zero for a sophisticated cyberattack that could have compromised thousands of environments worldwide.…
Read moreVMware Aria Operations 8.18 HF5: Enhancing Performance, Closing Security Gaps
VMware has recently released VMware Aria Operations 8.18 Patch 5, a crucial update aimed at enhancing stability, security, and functionality within Aria Operations environments. This patch specifically addresses multiple known issues, enhances security by mitigating critical vulnerabilities, and updates diagnostic management packs to include new VMware Security Advisories (VMSAs). Key issues resolved in Aria Operations…
Read moreVMware Releases Critical Security Updates for ESXi, Workstation, and Fusion (VMSA-2025-0004)
VMware has released critical and important security patches for VMware ESXi, VMware Workstation, and VMware Fusion to remediate multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226). These issues carry Critical and Important severity ratings with CVSSv3 base scores ranging from 7.1 to 9.3. Below is a summary of the vulnerabilities, along with links to the fixed versions and…
Read more