Broadcom security patch release for CVE-2025-41251
Security Patch Release
Summary
Hide ▲
Show ▼
Broadcom's VMware NSX security updates close two high-severity flaws that let unauthenticated attackers enumerate usernames and potentially progress to brute-force or unauthorized access attempts.
Related Happenings
Ivanti security patch release for CVE-2026-8043
Security Patch Release
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
**Ivanti, Fortinet, SAP, Broadcom, and n8n** released **security fixes** on **2026-05-18** for flaws that could enable **authentication bypass**, **remote code execution**, **SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: **Ivanti, Fortinet, SAP, Broadcom, and n8n** released **security fixes** on **2026-05-18** for flaws that could enable **authentication bypass**, **remote code execution**, **SQL...
Cisco security patch release for CVE-2026-20182
Security Patch Release
First: 14.05.2026 20:45
Last: 14.05.2026 20:45
Sources 1
About this happening:
Cisco released **updates** for **CVE-2026-20182**, a **maximum-severity authentication bypass** in **Catalyst SD-WAN Controller/Manager**, after the flaw was **exploited in limite...
Cisco security patch release for CVE-2026-20182
Security Patch ReleaseAbout this happening: Cisco released **updates** for **CVE-2026-20182**, a **maximum-severity authentication bypass** in **Catalyst SD-WAN Controller/Manager**, after the flaw was **exploited in limite...
TP-Link security patch release for CVE-2025-15517
Security Patch Release
First: 25.03.2026 13:11
Last: 25.03.2026 13:11
Sources 1
About this happening:
**TP-Link** released **security updates** for its **Archer NX** router series to close a critical authentication-bypass flaw that could let attackers upload firmware without loggi...
TP-Link security patch release for CVE-2025-15517
Security Patch ReleaseAbout this happening: **TP-Link** released **security updates** for its **Archer NX** router series to close a critical authentication-bypass flaw that could let attackers upload firmware without loggi...
Citrix security patch release for CVE-2026-3055
Security Patch Release
First: 24.03.2026 07:59
Last: 24.03.2026 07:59
Sources 1
About this happening:
Citrix's **NetScaler ADC** and **NetScaler Gateway** updates close **CVE-2026-3055** and **CVE-2026-4368**, including a flaw that could leak sensitive memory from configured appli...
Citrix security patch release for CVE-2026-3055
Security Patch ReleaseAbout this happening: Citrix's **NetScaler ADC** and **NetScaler Gateway** updates close **CVE-2026-3055** and **CVE-2026-4368**, including a flaw that could leak sensitive memory from configured appli...
Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Security Patch Release
First: 04.03.2026 21:12
Last: 04.03.2026 21:12
Sources 1
About this happening:
**Cisco Secure Firewall Management Center (FMC)** patch release for **CVE-2026-20131** and **CVE-2026-20079** addressed **CVSS 10** flaws that could let an **unauthenticated remot...
Cisco Secure Firewall Management Center patch release (CVE-2026-20079, CVE-2026-20131)
Security Patch ReleaseAbout this happening: **Cisco Secure Firewall Management Center (FMC)** patch release for **CVE-2026-20131** and **CVE-2026-20079** addressed **CVSS 10** flaws that could let an **unauthenticated remot...
Latest development: 20.03.2026 17:09
CISA ordered Federal Civilian Executive Branch (FCEB) agencies to apply security updates for CVE-2026-20131 in Cisco Secure Firewall Management Center (FMC) by Sunday, March 22 after Cisco updated its bulletin on March 18 to warn of active exploitation in the wild. Amazon threat intelligence researchers said Interlock ransomware had been exploiting CVE-2026-20131 as a zero-day since the end of January, and Cisco said the web-based management interface could let an unauthenticated, remote attacker execute arbitrary Java code as root on an affected device.
Timeline
-
30.09.2025 15:10 3 articles · 7mo ago
Broadcom patches VMware NSX username-enumeration flaws
Mitigation Patch UpdateBroadcom released security updates on 2025-09-29 to fix CVE-2025-41251 and CVE-2025-41252 in VMware NSX after the U.S. National Security Agency (NSA) reported the flaws. CVE-2025-41251 is a weakness in the password recovery mechanism, and both issues let unauthenticated attackers enumerate valid usernames that could support later brute-force or unauthorized access attempts.
Show sources
- Broadcom fixes high-severity VMware NSX bugs reported by NSA — www.bleepingcomputer.com — 30.09.2025 15:10
- Broadcom fixes high-severity VMware NSX bugs reported by NSA — www.bleepingcomputer.com — 30.09.2025 15:10
- Broadcom Issues Patches for VMware NSX and vCenter Security Flaws — www.infosecurity-magazine.com — 01.10.2025 18:45
-
30.09.2025 15:10 1 articles · 7mo ago
Broadcom publicly discloses the VMware NSX fixes
Initial DisclosureBroadcom publicly confirmed the VMware NSX fixes on 2025-09-30 and credited the U.S. National Security Agency (NSA) for reporting the issue, highlighting that CVE-2025-41251 and CVE-2025-41252 are high-severity username-enumeration flaws affecting VMware NSX deployments. The disclosures framed the bugs as conditions that could let unauthenticated attackers enumerate valid usernames and later attempt brute-force or unauthorized access.
Show sources
- Broadcom fixes high-severity VMware NSX bugs reported by NSA — www.bleepingcomputer.com — 30.09.2025 15:10