<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Broadcom</title><description>Actively exploited vulnerabilities affecting Broadcom products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/broadcom.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-59310 — Broadcom VMware vCenter Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-59310</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-59310</guid><description>This path traversal vulnerability in VMware vCenter is serious because vCenter is typically the administrative hub for entire virtualized environments. An attacker who can reach vCenter over the network — without needing to be inside a VPN or have credentials — could exploit this flaw to execute arbitrary code, potentially gaining control over every virtual machine and host managed by that vCenter instance. Compromise of vCenter is effectively compromise of the entire virtual infrastructure it manages.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>Broadcom</category><category>VMware vCenter</category></item><item><title>CVE-2026-22719 — Broadcom VMware Aria Operations Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-22719</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-22719</guid><description>This vulnerability in Broadcom VMware Aria Operations (formerly vRealize Operations) allows an unauthenticated attacker to inject commands that can lead to full remote code execution. No credentials are required to exploit it, making the attack surface broad. The flaw is triggered during support-assisted product migration workflows, meaning organizations actively migrating or receiving vendor support for migration may be at heightened risk. Successful exploitation could give attackers complete control over the affected system.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate><category>Broadcom</category><category>VMware Aria Operations</category></item><item><title>CVE-2024-37079 — Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-37079</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-37079</guid><description>This vulnerability in VMware vCenter Server allows an attacker with basic network access to the vCenter Server to send maliciously crafted packets targeting the DCERPC protocol implementation. A successful exploit could result in remote code execution — meaning an attacker could run arbitrary code on the server without valid credentials. Since vCenter Server is the central management plane for VMware virtualized environments, compromise could give attackers control over an entire virtual infrastructure.</description><pubDate>Fri, 23 Jan 2026 00:00:00 GMT</pubDate><category>Broadcom</category><category>VMware vCenter Server</category></item><item><title>CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-41244</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-41244</guid><description>This vulnerability allows a local, non-administrative user inside a virtual machine to escalate their privileges all the way to root on that same VM. The attack requires VMware Tools to be installed and the VM to be managed by Aria Operations with SDMP enabled — conditions common in enterprise VMware environments. A compromised or malicious user account that would otherwise have limited access could leverage this flaw to gain full control of the guest OS, posing serious risk to workloads and data.</description><pubDate>Thu, 30 Oct 2025 00:00:00 GMT</pubDate><category>Broadcom</category><category>VMware Aria Operations and VMware Tools</category></item></channel></rss>