Vendor
Broadcom vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in Broadcom: 0 in the last 7 days and 10 in the last 90 days, 13 of them critical and 11 exploited in the wild. The most recent, CVE-2026-63335, was published on 18 August 2026. 3 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 10
- Critical, all time
- 13
- Exploited in the wild
- 11
About Broadcom
A global technology leader that designs, develops, and supplies semiconductor and infrastructure software solutions, including the Spring framework via its VMware Tanzu division.
Broadcom technologies
Latest Broadcom vulnerabilities
- CVE-2026-63335: RabbitMQ Java client denial of service via malformed AMQP framemediumCVSS 6.3EPSS 0.5%
- CVE-2026-59310: VMware vCenter directory traversal in Syslog servercriticalexploited in the wildCVSS 9.8EPSS 2.6%
- CVE-2026-59327: Spring Tools for Eclipse cleartext storage of DevTools secretmediumCVSS 4.4
- CVE-2026-59326: Spring Boot language server credential disclosure in proxy logslowCVSS 3.3
- CVE-2026-47873: Spring Tools for Eclipse insecure port binding in Boot Dashboard Docker integrationhighCVSS 8
- CVE-2026-47858: Spring Tools JMX remote code execution in live information modehighCVSS 8
- CVE-2026-57219: RabbitMQ information disclosure in management API auth endpointinfoCVSS 8.7
- CVE-2026-57216: RabbitMQ authentication bypass for loopback-restricted usersmediumCVSS 6.8
- CVE-2026-57215: RabbitMQ incorrect authorization in amq.rabbitmq.reply-to bindingsinfoCVSS 7
- CVE-2026-57212: RabbitMQ resource exhaustion in management HTTP API via oversized JSONinfoCVSS 7.1
- CVE-2026-47838: VMware Spring Security user impersonation in SubjectDnX509PrincipalExtractormediumCVSS 6.8EPSS 0.1%
- CVE-2026-8370: Broadcom Automic Automation Agent Unix privilege escalationinfoCVSS 8.5
- CVE-2026-41713: VMware Spring AI prompt injection in conversation memoryhighCVSS 8.2EPSS 0.0%
- CVE-2026-41712: VMware Spring AI data exposure in chat memory componenthighCVSS 7.5EPSS 0.0%
- CVE-2026-22741: Spring Framework cache poisoning in static resource resolutionlowCVSS 3.1EPSS 0.2%
- CVE-2026-22751: Spring Spring Security TOCTOU race condition in JdbcOneTimeTokenServicemediumCVSS 4.8EPSS 0.1%
- CVE-2026-22719: Broadcom VMware Aria Operations command injection during migrationcriticalexploited in the wildCVSS 8.1EPSS 2.1%
- CVE-2024-37079: Broadcom VMware vCenter Server out-of-bounds write in DCERPC protocolcriticalexploited in the wildCVSS 9.8EPSS 82.0%
- CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools privilege escalationcriticalexploited in the wildCVSS 7.8EPSS 0.6%
- CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerabilitycriticalexploited in the wildCVSS 6.7
- CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-38813: VMware vCenter Server Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-22948: VMware vCenter Server Incorrect Default File Permissions Vulnerabilitycriticalexploited in the wildCVSS 6.5
- CVE-2024-3596: RADIUS Protocol MD5 collision forgery attack (Blast-RADIUS)criticalCVSS 9
- CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 9.8
Most severe Broadcom vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-37079: Broadcom VMware vCenter Server out-of-bounds write in DCERPC protocolcriticalexploited in the wildCVSS 9.8EPSS 82.0%
- CVE-2026-59310: VMware vCenter directory traversal in Syslog servercriticalexploited in the wildCVSS 9.8EPSS 2.6%
- CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-38813: VMware vCenter Server Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2026-22719: Broadcom VMware Aria Operations command injection during migrationcriticalexploited in the wildCVSS 8.1EPSS 2.1%
- CVE-2025-41244: Broadcom VMware Aria Operations and VMware Tools privilege escalationcriticalexploited in the wildCVSS 7.8EPSS 0.6%
- CVE-2025-1976: Broadcom Brocade Fabric OS Code Injection Vulnerabilitycriticalexploited in the wildCVSS 6.7
- CVE-2022-22948: VMware vCenter Server Incorrect Default File Permissions Vulnerabilitycriticalexploited in the wildCVSS 6.5
- CVE-2021-21973: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerabilitycriticalexploited in the wildCVSS 5.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 5 | 1 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/broadcom.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Broadcom vulnerabilities", https://junglewise.ai/threats/vendors/broadcom, 26 September 2026.