Broadcom known exploited vulnerabilities
CISA lists 5 Broadcom CVEs as exploited in the wild. 4 were added in the last 12 months (latest 2026-08-18), and 1 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-37079 (VMware vCenter Server): EPSS 22.4%, added 2026-01-23
- CVE-2026-22719 (VMware Aria Operations): EPSS 17.7%, added 2026-03-03
- CVE-2025-41244 (VMware Aria Operations and VMware Tools): EPSS 8.4%, added 2025-10-30
- CVE-2026-59310 (VMware vCenter): EPSS 2.6%, added 2026-08-18
- CVE-2025-1976 (Brocade Fabric OS): EPSS 0.7%, added 2025-04-28
Most affected Broadcom products
VMware vCenter (1), VMware Aria Operations (1), VMware vCenter Server (1), VMware Aria Operations and VMware Tools (1), Brocade Fabric OS (1).
All Broadcom CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-59310 | VMware vCenter | VMware vCenter Path Traversal | 2026-08-18 | 2026-08-21 | 2.6% | Yes |
| CVE-2026-22719 | VMware Aria Operations | VMware Aria Operations Command Injection | 2026-03-03 | 2026-03-24 | 17.7% | – |
| CVE-2024-37079 | VMware vCenter Server | VMware vCenter Server Out-of-bounds Write | 2026-01-23 | 2026-02-13 | 22.4% | – |
| CVE-2025-41244 | VMware Aria Operations and VMware Tools | VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions | 2025-10-30 | 2025-11-20 | 8.4% | – |
| CVE-2025-1976 | Brocade Fabric OS | Brocade Fabric OS Code Injection | 2025-04-28 | 2025-05-19 | 0.7% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors