Vulnerabilities

VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched

Four CVEs disclosed at the Pwn2Own Berlin 2025 hacking competition have been patched in VMware products.

VMware

Broadcom informed customers this week that several VMware product vulnerabilities disclosed earlier this year at the Pwn2Own hacking competition have been patched.

Participants earned more than $1 million at the Pwn2Own Berlin 2025 competition organized by Trend Micro’s Zero Day Initiative (ZDI). More than $340,000 was paid out for exploits targeting VMware products.

The STARLabs SG team earned $150,000 for exploiting a single integer overflow bug to hack VMware ESXi. 

According to Broadcom’s advisory, this critical bug impacts the VMXNET3 virtual network adapter and it can allow an attacker with local admin privileges on a VM that uses the adapter to execute arbitrary code on the host. The security hole is tracked as CVE-2025-41236.

The REverse Tactics team earned $112,500 for an ESXi exploit involving two bugs. The amount is lower than the one earned by STARLabs SG because one of the flaws was known to Broadcom. 

REverse Tactics has been credited by Broadcom for two CVEs: CVE-2025-41237, a critical out-of-bounds write vulnerability that can be exploited by a privileged attacker on a VM to execute arbitrary code on the host, and CVE-2025-41239, a high-severity issue that allows a privileged attacker to leak memory.

Advertisement. Scroll to continue reading.

A researcher from Theori, a company that was also represented at Pwn2Own but did not target VMware, has also been credited for independently discovering CVE-2025-41239.

Lastly, the Synacktiv team earned $80,000 at Pwn2Own for a VMware Workstation exploit. Broadcom’s advisory credits Synacktiv for CVE-2025-41238, a critical out-of-bounds write issue that can allow an attacker with local admin privileges on a VM to execute arbitrary code on the host. 

The vendor has released patches for these vulnerabilities for VMware ESXi, Workstation, Fusion, Cloud Foundation, XSphere Foundation, Telco Cloud Platform, and Tools. 

In a separate FAQ document, Broadcom said it has no evidence that these vulnerabilities have been exploited in the wild. 

Industrial giant Rockwell Automation on Wednesday also published an advisory to inform customers about these VMware vulnerabilities. Several Rockwell products that may use VMware components are impacted, including Industrial Data Center (IDC), VersaVirtual Appliance (VVA), Threat Detection Managed Services (TDMS), Endpoint Protection Service, and Engineered and Integrated Solutions.

Related: NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch

Related: Vulnerabilities Patched by Juniper, VMware and Zoom

Related: Vulnerabilities Patched by Ivanti, VMware, Zoom

Related Content

Artificial Intelligence

Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.

Vulnerabilities

The major browser update resolves roughly 80 critical- and high-severity security defects.

Vulnerabilities

The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. 

Vulnerabilities

A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.

Artificial Intelligence

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.

Endpoint Security

Apple announced that dozens of vulnerabilities have been patched in each of its operating systems.

Funding/M&A

Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments.

Vulnerabilities

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version