Skip to content
COOEY

FAIL › dossier

Broadcom

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 50%

Broadcom has a history of high-severity vulnerabilities in its products, including remote code execution and privilege escalation issues.

PROFILE
CategorySemiconductorWhat they doBroadcom Inc. is a global leader in semiconductor solutions, designing and manufacturing a wide range of chips for various computing, networking, and storage applications.
SECURITY POSTURE

Broadcom has faced multiple high-severity vulnerabilities in its products, indicating potential weaknesses in its security posture.

Notable failures
  • CVE-2026-22719 (high [RCE])
  • CVE-2024-37079 (high [RCE])
  • CVE-2025-41244 (high [RCE])
  • CVE-2025-1976 (high [RCE])
  • CVE-2026-57216 (medium)
  • CVE-2026-57211 (medium)
Patterns: Unpatched command injection flaws; Out-of-bounds write vulnerabilities; Local non-admins escalating privileges; Code injection vulnerabilities
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2026-08-18 CVE-2026-59310 high Unauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors.
2026-03-03 CVE-2026-22719 high Broadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations.
2026-01-23 CVE-2024-37079 high Broadcom's VMware vCenter Server exploited for RCE due to unpatched out-of-bounds write in DCERPC protocol
2025-10-30 CVE-2025-41244 high Broadcom's VMware Aria Operations and VMware Tools allow local non-admins to escalate to root via unpatched SDMP vulnerability.
2025-04-28 CVE-2025-1976 high A Broadcom Brocade Fabric OS vulnerability allows local admins to execute arbitrary code with root privileges, and is currently being exploited in the wild.
2026-07-10 CVE-2026-57216 medium RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol pat
2026-07-10 CVE-2026-57211 medium RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extensio
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
2018-04-11 CVE-2018-1273 critical CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older
FEDRAMP CATALOG PRODUCTS · 4
PRODUCTSTATUSIMPACT
ClarityAuthorizedModerate
General Support Systems (GSS)AuthorizedModerate
RallyAuthorizedModerate
Symantec Gov Cloud Security (GCS)In ProcessModerate
Open questions: How has Broadcom addressed these vulnerabilities? · What is the company's current security posture? · Are there any ongoing or future security concerns related to Broadcom's products?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:43:11.556298+00:00