VMware (Broadcom)
VMware virtualization and cloud infrastructure from Broadcom - VCF, vSphere, NSX, VMware Cloud on AWS, Live Recovery and Tanzu.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001 | Accredited certification body | Broadcom Cloud Services ISMS. VMware services in scope: VMware Cloud on AWS, VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth. On-premises products (VCF, vSphere/ESXi, vCenter, NSX) are NOT in the cloud ISMS scope. | — | — | Current |
| ISO/IEC 27017:2015 | Accredited certification body | Cloud-specific information security guidance. VMware Cloud on AWS ONLY - no other VMware or Tanzu service is in scope. | — | — | Current |
| ISO/IEC 27018:2019 | Accredited certification body | Protection of PII in public cloud as a PII processor. VMware Cloud on AWS ONLY. | — | — | Current |
| ISO 9001:2015 | Accredited certification body | Quality management system. VMware Cloud on AWS is the ONLY VMware service listed in scope. | — | — | Current |
| SOC 1 | Independent third-party CPA firm | VMware Cloud on AWS, VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth. Report download requires the Broadcom Support Portal and an NDA. | — | — | Current |
| SOC 2 | Independent third-party CPA firm | VMware Cloud on AWS, VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth. Report download requires the Broadcom Support Portal and an NDA. Bridge letters are available. | — | — | Current |
| SOC 3 | Independent third-party CPA firm | Tanzu CloudHealth is the ONLY VMware/Tanzu service with a SOC 3 report. VMware Cloud on AWS, Live Cyber Recovery, Avi Load Balancer and vDefend ATP do NOT have SOC 3. | — | — | Current |
| PCI DSS | Qualified Security Assessor (QSA) | VMware Cloud on AWS ONLY. No other VMware service is PCI DSS in scope; PCI 3DS covers only the Arcot payment products, not VMware. | — | — | Current |
| HIPAA Business Associate Agreement | Contractual commitment (not a certification) | Broadcom will enter into a HIPAA BAA for VMware Cloud on AWS and VMware Live Cyber Recovery ONLY. No other VMware service is BAA-eligible. | — | — | Current |
| Cyber Essentials | UK NCSC-backed scheme via accredited certification body | VMware Cloud Foundation ONLY. No other VMware, Tanzu or Symantec service is in the Cyber Essentials scope. | — | — | Current |
| Cyber Essentials Plus | Accredited third party (annual external vulnerability testing) | VMware Cloud Foundation ONLY. Requires an accredited third party to conduct external vulnerability testing annually. | — | — | Current |
| TruSight Assessment | TruSight Solutions (bank-created third-party assessment utility) | Broadcom-wide participation. Completed assessment reports are purchased directly from TruSight ([email protected]), not from Broadcom. | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| No VMware or Broadcom penetration test report or testing cadence is published on the trust centre. The only published third-party technical testing is the annual external vulnerability testing required for Cyber Essentials Plus on VMware Cloud Foundation. VMware runs a mature vulnerability response programme (vSRC) and participates in Pwn2Own, where researchers target ESXi, Workstation and vCenter. (date = profile capture date) | Not published. Accredited third party performs annual external vulnerability testing for Cyber Essentials Plus (VMware Cloud Foundation only). | Aug. 6, 2026 | Annual | Not Available |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting provider and platform services for VMware Cloud on AWS | US, UK, Germany, Ireland, France, Italy, Sweden, Switzerland, Canada, Brazil, Australia, Japan, South Korea, India, Hong Kong SAR, Bahrain, South Africa | View ↗ |
| Amazon Web Services (AWS) | Hosting provider and platform services for VMware Live Recovery | US, Ireland, UK, France, Germany, Italy, Sweden, Switzerland, Canada, Brazil, Australia, Singapore, Japan, South Korea, India, Hong Kong SAR, Bahrain, South Africa | View ↗ |
| Amazon Web Services (AWS) | Hosting provider and platform services for Tanzu Application Catalog, Tanzu CloudHealth, DX OpenExplore and Carbon Black On Prem EDR | United States | View ↗ |
| Google LLC | Hosting provider and platform services for VMware vDefend Firewall and vDefend Firewall with Advanced Threat Prevention | United States, Germany, South Korea, Australia | View ↗ |
| Google LLC | Hosting provider and platform services for VMware Avi Load Balancer | United States, Japan, Ireland | View ↗ |
| Google LLC | Hosting provider and platform services for Tanzu CloudHealth | United States, Germany, United Kingdom | View ↗ |
| Google LLC | Hosting, SSO, authentication, observability pipeline, email delivery monitoring and product feedback for Tanzu Mission Control SaaS | United States, Ireland, Japan, Canada | View ↗ |
| Google LLC | Hosting provider and platform services for VMware Cloud Web Security | United States | View ↗ |
| Microsoft | OpenAI service for VMware Tanzu Insights | United States | View ↗ |
| Cloudflare, Inc. | Infrastructure management for VMware Cloud Web Security | United States | View ↗ |
| Elasticsearch Inc. | Security services, logging and monitoring for VMware Cloud Web Security, VMware NSX, VMware NSX Defender and VMware NSX Detonator | United States, Belgium | View ↗ |
| Fullstory Inc. | Product usage clickstream analytics for VMware Cloud on AWS | United States | — |
| Aha! Labs Inc. | Gather and process product feedback for Tanzu CloudHealth | United States | — |
| Pendo.io, Inc. | Product analytics and usage telemetry for Tanzu CloudHealth (and Symantec Endpoint Security, CBX) | United States | View ↗ |
| Sensu | Observability pipeline and monitoring for Tanzu CloudHealth | United States | — |
| TeleSign Corporation | Optional delivery of SMS one-time passwords - listed against ALL Broadcom products | United States | — |
| Xyleme Inc. | Learning management system and education services - listed against ALL Broadcom products | United States | — |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| July 29, 2026 | VMSA-2026-0006.1 (Broadcom notification VCDSA38017): five privately reported vulnerabilities in VMware ESX, vCenter, Workstation and Fusion, CVSSv3 range 2.7-9.8. Includes a vCenter VMware Directory Service authentication bypass (CVE-2026-59309, 9.8) and a vCenter Syslog directory traversal allowing arbitrary code execution (CVE-2026-59310, 9.8). Reported by Atredis Partners and by STARLabs SG via Pwn2Own/ZDI. | Affects VMware ESX, vCenter, Workstation, Fusion, VMware Cloud Foundation, vSphere Foundation, Telco Cloud Platform and Telco Cloud Infrastructure. An attacker with network access to vCenter could bypass authentication or execute code; a local VM administrator could escape to the host via a VMXNET3 out-of-bounds write (CVE-2026-47876, 9.3). No workarounds available for any of the five issues. | Cumulative patches: vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k and 8.0 U2f; ESXi 9.1.0.0200-25557999 and 9.0.2.0100-25595025. Telco Cloud per KB449886; VCF 5.x async patching per KB88287. Supplemental FAQ at brcm.tech/vmsa-2026-0006. Advisory status still OPEN, last updated 03 August 2026. | Report ↗ |
| March 4, 2025 | VMSA-2025-0004 (VCDSA25390): three vulnerabilities in VMware ESXi, Workstation and Fusion, CVSSv3 range 7.1-9.3. Broadcom stated it had information to suggest that exploitation of all three issues had occurred in the wild. All three were reported by the Microsoft Threat Intelligence Center. | CVE-2025-22224 (9.3) is a VMCI TOCTOU out-of-bounds write letting a VM administrator run code as the host VMX process. CVE-2025-22225 (8.2) allows an arbitrary kernel write and sandbox escape. CVE-2025-22226 (7.1) leaks VMX process memory via an HGFS out-of-bounds read. Affected VMware ESXi, Workstation Pro/Player, Fusion, VMware Cloud Foundation and Telco Cloud Platform. Chained, these permit guest-to-host escape. | Patches published the same day as the advisory, including ESXi80U3d-24585383 and ESXi80U2d-24585300. No workarounds were available, so patching was the only remediation. With confirmed in-the-wild exploitation this was an emergency-patch event for hypervisor estates. Advisory status OPEN, last updated 04 March 2025. | Report ↗ |
| Oct. 23, 2023 | VMSA-2023-0023 (VCDSA23677): an out-of-bounds write in the vCenter Server DCERPC implementation (CVE-2023-34048, CVSS 9.8) and a partial information disclosure (CVE-2023-34056, CVSS 4.3). VMware subsequently confirmed that exploitation of CVE-2023-34048 had occurred in the wild. Reported via Trend Micro Zero Day Initiative and Deiteriy Lab. | An actor with only network access to vCenter Server could trigger the out-of-bounds write and potentially achieve remote code execution, compromising the management plane of the whole virtual estate. CVE-2023-34056 let a non-administrative vCenter user reach unauthorised data. Affected VMware vCenter Server and VMware Cloud Foundation. | In-product workarounds were investigated and found not viable. Given the severity, VMware issued patches even for end-of-life releases (vCenter 6.7U3, 6.5U3, VCF 3.x) plus extra patches for 8.0U1, and async patches for VCF 5.x and 4.x per KB88287. Advisory is CLOSED, last updated 15 January 2024. | Report ↗ |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| VMware External Vulnerability Response and Remediation Policy | Public | View ↗ |
| Broadcom Privacy Policy | Public | View ↗ |
| Cookie Policy | Public | View ↗ |
| Data Processing and Data Transfers Statement | Public | View ↗ |
| Third Party List (sub-processors) | Public | View ↗ |
| Enterprise Software Products & Services Transparency Notices | Public | View ↗ |
| VMware Usage Data Programs Notice | Public | View ↗ |
| Data Processing Addendum (Global Customers) | Public | View ↗ |
| EU Data Act Addendum | Public | View ↗ |
| Supplier Responsibility Standards | Public | View ↗ |
| Compliance artifact library (SOC 1/2/3, ISO certificates, HIPAA and PCI documentation) | On Request | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative No named Article 27 representative or DPO published. Broadcom names Ireland's Data Protection Commission as its GDPR Lead Supervisory Authority for the software business; requests go via the Contact Broadcom section of the Privacy Policy (web form).
- Lawful Basis Broadcom relies on: legitimate interests in providing the sites and services and doing business with your organisation; consent, withdrawable at any time via contextual preference tools; performance of a contract, for example order fulfilment; and compliance with legal obligations. A separate legitimate-interest basis is asserted for fraud prevention and network and information security when delivering services. Cross-border transfers use EU SCCs, the UK IDTA and Chinese SCCs under PIPL.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform No public bug bounty or monetary reward. vSRC takes private reports at [email protected] (PGP key legacyId=1055), offers researcher credit only, and publishes an explicit safe-harbour commitment. VMware is a CVE Numbering Authority (CNA).
Trust Portal & Audit Evidence
**Trust centre:** Broadcom Trust Center at broadcom.com/support/trust-center, with the certification index at broadcom.com/support/trust-center/compliance. Certifications are listed per service and per region, and the filters make clear that most VMware attestations cover only a small subset of the portfolio.
**Audit evidence access:** there is no self-service trust portal. Compliance artifacts (SOC reports, ISO certificates, HIPAA and PCI documentation) sit behind the Broadcom Support Portal in the Product Legal Documentation module and require an Enterprise User Profile, which is a two-step upgrade from a Basic account. Download instructions are published as notification 37107 (first published 25 February 2026, last updated 09 March 2026).
**TruSight:** Broadcom participates in TruSight, but reports are purchased directly from TruSight ([email protected]) rather than obtained from Broadcom.
**Security advisories:** the public VMware Security Advisories index is at broadcom.com/support/vmware-security-advisories. It has no per-advisory deep links; the searchable advisory table lives on the Support Portal at support.broadcom.com/web/ecx/security-advisory, segmented as VC (VMware Cloud Foundation), VT (Tanzu) and VA (Application Networking and Security). At the review date the VMware Cloud Foundation segment held 340 advisories.
**Vulnerability policy:** VMware External Vulnerability Response and Remediation Policy at broadcom.com/support/vmware-services/security-response. PSIRT contact [email protected]; PGP key at knowledge.broadcom.com/external/article?legacyId=1055.
**Sub-processors:** Broadcom Third Party List at broadcom.com/company/legal/privacy/third-party-list, last updated 30 July 2026.
**Scope warning:** VMware End User Computing (Horizon, Workspace ONE) was divested to Omnissa and is out of scope for Broadcom trust documentation. Omnissa must be assessed separately at omnissa.com.
Risk Assessment Notes
**Inherent risk drivers**
- Hypervisor and management-plane concentration: vCenter and ESX sit beneath large parts of the estate, so a single critical vulnerability has estate-wide blast radius.
- Repeated confirmed in-the-wild exploitation of critical, network-reachable vCenter and ESXi flaws (CVE-2023-34048 in 2023; CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226 in 2025).
- Workarounds are frequently unavailable, so patching is often the only remediation and the patch window becomes the entire control.
- Predominantly on-premises software: the customer, not Broadcom, owns patching, hardening, segmentation, backup and monitoring.
**Certification scope is narrow - always check per service**
- ISO/IEC 27001: only VMware Cloud on AWS (which also holds 27017 and 27018), VMware Live Cyber Recovery, VMware Avi Load Balancer, VMware vDefend Advanced Threat Prevention and Tanzu CloudHealth.
- SOC 1 and SOC 2: VMware Cloud on AWS, Live Cyber Recovery, Avi Load Balancer and vDefend ATP. Tanzu CloudHealth is the only service with a SOC 3.
- PCI DSS and ISO 9001: VMware Cloud on AWS only. HIPAA BAA: VMware Cloud on AWS and VMware Live Cyber Recovery only.
- Cyber Essentials and Cyber Essentials Plus: VMware Cloud Foundation only.
- IRAP: no VMware service is in scope, all IRAP entries are Symantec. PCI 3DS: Arcot only. TISAX: the semiconductor business only.
- Practical consequence: on-premises VMware Cloud Foundation, vSphere, NSX and Tanzu deployments sit largely outside the audited service perimeter, so an attestation should not be assumed to cover the SKU you are buying.
**Mitigating factors**
- Mature, well-documented PSIRT: VMware is an approved CVE Numbering Authority and publishes structured VMSAs with CVSS scores, known attack vectors, response matrices and explicit notes when exploitation is happening in the wild.
- Advisories are prompt and usually coordinated with patch availability, with supplemental FAQs for critical events.
- Broadcom has patched end-of-life versions where severity warranted it, for example vCenter 6.7U3, 6.5U3 and VCF 3.x under VMSA-2023-0023.
- Published Data Processing Addendum, EU Data Act Addendum, transparency notices and a dated third-party list.
- Explicit safe-harbour commitment for good-faith security researchers.
**Residual responsibilities for the customer**
- Subscribe to Broadcom security alerts and maintain an emergency patch path for Critical VMSAs; treat vCenter and ESX as tier-0 assets.
- Restrict management-plane network reachability and never expose vCenter to untrusted networks.
- Confirm the specific service or SKU being purchased is inside a certified scope before relying on any attestation.
- Assess Omnissa separately for Horizon and Workspace ONE.
- Own backup, replication and DR design for on-premises deployments.
**Evidence gaps at review date**
- No self-service trust portal; audit evidence requires an Enterprise Support Portal profile, which adds friction to annual due diligence.
- No public bug bounty and no published penetration-test summary for on-premises products; visible external assurance comes mainly through Pwn2Own and Zero Day Initiative submissions.
- No published RTO, RPO or uptime SLA on the public trust centre for VMware services.
- No named Article 27 EU representative or Data Protection Officer.
**Suggested review cadence:** annual, with continuous monitoring of VMSAs and an out-of-cycle review triggered by any Critical advisory affecting a deployed product.
Copyright © 2026 SnapGRC