FAIL › dossier
Broadcom
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 50%
Broadcom has a history of high-severity vulnerabilities in its products, including remote code execution and privilege escalation issues.
PROFILE
CategorySemiconductorWhat they doBroadcom Inc. is a global leader in semiconductor solutions, designing and manufacturing a wide range of chips for various computing, networking, and storage applications.
SECURITY POSTURE
Broadcom has faced multiple high-severity vulnerabilities in its products, indicating potential weaknesses in its security posture.
Notable failures
- CVE-2026-22719 (high [RCE])
- CVE-2024-37079 (high [RCE])
- CVE-2025-41244 (high [RCE])
- CVE-2025-1976 (high [RCE])
- CVE-2026-57216 (medium)
- CVE-2026-57211 (medium)
Patterns: Unpatched command injection flaws; Out-of-bounds write vulnerabilities; Local non-admins escalating privileges; Code injection vulnerabilities
FAILURE HISTORY · 9
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-08-18 | CVE-2026-59310 | high | Unauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors. |
| 2026-03-03 | CVE-2026-22719 | high | Broadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations. |
| 2026-01-23 | CVE-2024-37079 | high | Broadcom's VMware vCenter Server exploited for RCE due to unpatched out-of-bounds write in DCERPC protocol |
| 2025-10-30 | CVE-2025-41244 | high | Broadcom's VMware Aria Operations and VMware Tools allow local non-admins to escalate to root via unpatched SDMP vulnerability. |
| 2025-04-28 | CVE-2025-1976 | high | A Broadcom Brocade Fabric OS vulnerability allows local admins to execute arbitrary code with root privileges, and is currently being exploited in the wild. |
| 2026-07-10 | CVE-2026-57216 | medium | RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol pat |
| 2026-07-10 | CVE-2026-57211 | medium | RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extensio |
| 2021-09-16 | CVE-2021-40438 | critical | CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig |
| 2018-04-11 | CVE-2018-1273 | critical | CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older |
FEDRAMP CATALOG PRODUCTS · 4
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Clarity | Authorized | Moderate |
| General Support Systems (GSS) | Authorized | Moderate |
| Rally | Authorized | Moderate |
| Symantec Gov Cloud Security (GCS) | In Process | Moderate |
Open questions: How has Broadcom addressed these vulnerabilities? · What is the company's current security posture? · Are there any ongoing or future security concerns related to Broadcom's products?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:43:11.556298+00:00