Skip to content
Threat Feed

Tag

Esxi

30 briefs RSS
critical advisory

Critical Vulnerabilities in VMware vCenter and ESX Products

Multiple critical vulnerabilities, including CVE-2026-59309 and CVE-2026-59310 with CVSS 9.8, affect VMware vCenter and ESX/ESXi products, enabling unauthorized access without credentials, arbitrary code execution, virtualization escape, information disclosure, and defense evasion, which could lead to full system compromise and data breaches.

PoC VMware vCenter +13 virtualization critical-vulnerability rce unauthorized-access privilege-escalation defense-evasion esxi vcenter
5t 4c updated
medium advisory

ESXi External Root Login Detection

This detection identifies instances where the ESXi UI is accessed using the root account instead of a delegated administrative user, which bypasses role-based access controls and may indicate risky behavior or unauthorized activity.

ESXi +3 vmware root_login privilege_escalation
2r 1t
medium advisory

ESXi System Information Discovery via ESXCLI

Adversaries may use ESXCLI system-level commands to retrieve configuration details on VMware ESXi hosts for reconnaissance purposes, potentially leading to further compromise.

ESXi reconnaissance vmware
2r 1t
high advisory

ESXi System Clock Manipulation for Evasion

An attacker manipulates the system clock on an ESXi host to potentially evade detection, disrupt logging, or invalidate security controls, as seen in ESXi Post Compromise scenarios and Black Basta ransomware incidents.

ESXi clock-manipulation defense-evasion ransomware
2r 1t
high advisory

ESXi Root Account Compromise Indication

The detection identifies potentially compromised root accounts on ESXi hosts by monitoring the number of unique IP addresses logging in as root within a short time window, indicating credential misuse or lateral movement.

ESXi vmware root-account compromise lateral-movement credential-access
2r 2t
high advisory

ESXi Host Reverse Shell Detection

This detection identifies reverse shell string patterns on an ESXi host via syslog, potentially indicating a threat actor attempting to establish remote control over the system, which may lead to further compromise such as ransomware deployment.

ESXi reverse-shell vmware syslog ransomware
3r 1t
high advisory

ESXi Audit Tampering via esxcli

Attackers use esxcli system auditrecords commands on ESXi hosts to tamper with logging, hindering forensic analysis and detection efforts, potentially leading to prolonged compromise and data breaches.

ESXi audit-tampering defense-evasion vmware
3r 2t
high advisory

ESXi VM Exfiltration via Remote Tool

Attackers or malicious insiders may leverage remote tools and the NFC protocol to download virtual machine disk files from ESXi datastores, potentially leading to sensitive data exfiltration.

ESXi vmware exfiltration t1005
2r 1t
high advisory

ESXi VIB Acceptance Level Tampering

Attackers modify the ESXi VIB acceptance level to install unsigned or unverified software, weakening the host's integrity enforcement.

ESXi +1 vib tampering vmware
2r 1t
high advisory

ESXi User Granted Administrator Role

A user being granted the Administrator role on an ESXi host is a critical action that can indicate potential malicious behavior, as adversaries may use this to escalate privileges, maintain persistence, or disable security controls.

ESXi vmware privilege-escalation ransomware
2r 2t
high advisory

ESXi Syslog Configuration Changes via esxcli

Detection of ESXi syslog configuration changes via esxcli command, potentially indicating an attempt to disrupt logging and evade detection.

ESXi +3 syslog vmware defense-evasion t1562.003 t1690 black-basta
2r 1t
high threat

ESXi Syslog Configuration Change via esxcli

Detection of ESXi syslog configuration changes using esxcli, potentially indicating an attempt to disrupt logging and evade detection, with known association to Black Basta ransomware.

ESXi Black Basta +2 syslog vmware defense-evasion black-basta
2r 1t
medium advisory

ESXi SSH Enabled Detection

The enabling of SSH on ESXi hosts, as detected in ESXi Syslog, can signal malicious lateral movement by threat actors aiming for persistent access.

ESXi ssh lateral-movement
2r 1t
high advisory

ESXi SSH Brute-Force Attack Attempt

Detection of a potential brute-force attack against an ESXi host via SSH by monitoring for a high number of failed login attempts within a short time frame, indicating an attacker attempting to gain unauthorized access.

ESXi ssh brute-force credential-access vmware
2r 1t
medium advisory

ESXi Shell Enabled Detection

The ESXi Shell being enabled on a host may indicate malicious activity like preparing to execute commands locally or establishing persistent access.

ESXi vmware shell-access lateral-movement
2r 1t
high advisory

ESXi Sensitive File Access Attempt

An adversary attempts to access sensitive system and configuration files on an ESXi host, potentially for reconnaissance, credential harvesting, privilege escalation, lateral movement, or persistence.

ESXi credential-access discovery linux
2r 2t
high advisory

ESXi Lockdown Mode Disabled

Detection of ESXi Lockdown Mode being disabled, potentially indicating attacker attempts to weaken host security controls for broader access, data exfiltration, or VM tampering.

ESXi vmware lockdown mode defense evasion t1562
2r 1t
high advisory

ESXi Firewall Disabled Detection

This detection identifies when the ESXi firewall is disabled or set to permissive mode, potentially exposing the host to unauthorized access and network-based attacks, often preceding lateral movement, data exfiltration, or malware installation.

ESXi +3 firewall lateral_movement data_exfiltration ransomware attack.defense_evasion
2r
high advisory

ESXi Firewall Disabled

The ESXi firewall being disabled or set to permissive mode can expose the host to unauthorized access and network-based attacks, often preceding lateral movement, data exfiltration, or malware installation.

ESXi vmware firewall defense-evasion
2r 1t
high advisory

ESXi External Root Login Activity Detection

Detection of ESXi UI access using the root account from external IP addresses, bypassing role-based access controls and potentially indicating unauthorized activity or compromised credentials.

ESXi vmware root_login unauthorized_access t1078
2r 1t
high advisory

ESXi Encryption Settings Modified

Attackers modify ESXi host encryption settings, such as disabling secure boot or executable verification, to weaken hypervisor integrity and enable unauthorized code execution.

ESXi encryption vmware defense-evasion privilege-escalation
2r 2t
high advisory

ESXi Encryption Settings Modification

Detection of modifications to ESXi host encryption settings, such as disabling secure boot or executable verification, which may indicate attempts to weaken hypervisor integrity and allow unauthorized code execution.

ESXi +3 encryption vmware hypervisor attack.persistence
2r
medium advisory

ESXi Download Error Detection

Detection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.

ESXi +3 vmware syslog anomaly T1601.001 T1685 ESXi Post Compromise Black Basta Ransomware Infrastructure +1
2r 2t
high advisory

ESXi Bulk VM Termination Detection

Detection of abrupt virtual machine termination on ESXi hosts, potentially indicating denial-of-service, ransomware staging, or destruction of critical workloads.

ESXi vmware virtual_machine ransomware denial_of_service
2r 2t
high advisory

ESXi Audit Tampering Detection

Detection identifies the use of the esxcli system auditrecords commands to tamper with logging on an ESXi host, potentially evading detection and hindering forensic analysis.

ESXi +3 vmware audit-tampering defense-evasion
2r 1t
medium advisory

Detection of Failed ESXi File Downloads

This detection identifies failed file download attempts on ESXi hosts by looking for specific error messages in system logs, potentially indicating unauthorized attempts to install malicious components or scripts.

ESXi vmware download-error anomaly black-basta
2r 2t
high advisory

ESXi Loghost Configuration Tampering

Attackers modify the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response efforts after a compromise.

ESXi vmware syslog defense-evasion t1562
2r 1t
high advisory

ESXi Account Modification Detection

Detection of local user account creation, deletion, or modification on an ESXi host, potentially indicating unauthorized access, persistence attempts, or defense evasion.

ESXi vmware account-management persistence privilege-escalation
2r 7t
medium advisory

ESXi VM Discovery via ESXCLI Commands

Adversaries may use ESXCLI commands to discover virtual machines on an ESXi host, potentially indicating reconnaissance for high-value targets, environment mapping, or preparation for data theft or destructive operations.

VMware ESXi esxi vmware discovery
2r
high advisory

ESXi Loghost Configuration Tampering

An attacker modifies the ESXi host's syslog configuration to disrupt log forwarding, potentially evading detection and hindering incident response.

ESXi +3 syslog loghost tampering defense-evasion
2r 1t