Broadcom fixes high-severity VMware NSX bugs reported by NSA
The U.S. National Security Agency (NSA) has identified two high-severity VMware NSX vulnerabilities, which Broadcom has patched with security upgrades.
Administrators may deploy both classic and new applications in private and hybrid clouds with VMware NSX, a networking virtualization technology that is part of VMware Cloud Foundation.
The NSA's initial security vulnerability, identified as CVE-2025-41251, is caused by a fault in the password recovery process that allows unauthenticated attackers to list legitimate usernames for use in brute-force assaults.
Unauthenticated threat actors can also utilize the second one (CVE-2025-41252), a username enumeration vulnerability, to list legitimate usernames, which may result in attempts at unauthorized access.
In a security advisory...

