Vendor

Broadcom

As of , 5 Broadcom vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 3 were added in 2026. Patch first: CVE-2026-59310.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2026-59310Path TraversalBroadcom VMware vCenterPatch nowForensic triage required by CISA; ransomware use, listed within a year0.03
2CVE-2026-22719Command InjectionBroadcom VMware Aria OperationsPatch soon0.18
3CVE-2024-37079Out-of-bounds WriteBroadcom VMware vCenter ServerPatch soon0.22
4CVE-2025-41244Privilege Defined with Unsafe ActionsBroadcom VMware Aria Operations and VMware ToolsPatch soon0.08
5CVE-2025-1976Code InjectionBroadcom Brocade Fabric OSPatch soon0.01

Products

  • Brocade Fabric OS1 entry
  • VMware Aria Operations1 entry
  • VMware Aria Operations and VMware Tools1 entry
  • VMware vCenter1 entry
  • VMware vCenter Server1 entry

Added each year

1232025: 2220252026: 332026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20252
20263

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-59310 Broadcom VMware vCenterRansomware use: Unknown to Known.

Every change we recorded