CISA issued an urgent alert on March 4, 2025, adding three critical VMware vulnerabilities to its KEV catalog after confirmed exploitation. The flaws allow privilege escalation and sensitive data exfiltration in VMware products, discovered by Microsoft. Broadcom released patches, emphasizing immediate remediation to prevent large-scale breaches and protect critical infrastructure.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered