CyberMax
Home › Exploited CVEs

Broadcom known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 Broadcom CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-08-18), and 1 are known to be used in ransomware campaigns.

Broadcom CVEs added to CISA KEV per year
2025: 2202522026: 320263

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Broadcom products

VMware vCenter (1), VMware Aria Operations (1), VMware vCenter Server (1), VMware Aria Operations and VMware Tools (1), Brocade Fabric OS (1).

All Broadcom CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-59310VMware vCenterVMware vCenter Path Traversal2026-08-182026-08-212.6%Yes
CVE-2026-22719VMware Aria OperationsVMware Aria Operations Command Injection2026-03-032026-03-2417.7%–
CVE-2024-37079VMware vCenter ServerVMware vCenter Server Out-of-bounds Write2026-01-232026-02-1322.4%–
CVE-2025-41244VMware Aria Operations and VMware ToolsVMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions2025-10-302025-11-208.4%–
CVE-2025-1976Brocade Fabric OSBrocade Fabric OS Code Injection2025-04-282025-05-190.7%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors