Four critical vulnerabilities discovered at the Pwn2Own Berlin 2025 hacking competition have been patched in various VMware products, with hackers earning over $340,000 for their exploits. Broadcom, the parent company of VMware, confirmed that there is no evidence these flaws have been exploited in the wild.
Broadcom has issued security updates to address two high-severity vulnerabilities in VMware NSX, both reported by the NSA, which allow unauthenticated attackers to enumerate valid usernames. Additionally, several other security flaws in VMware products were disclosed, highlighting ongoing threats from state-sponsored hackers and cybercriminals targeting VMware's widely used solutions.