endoflife.ai
EOL Checker Products EOL Watch Get Support

ESXi 6.5, 6.7, and 7.0 CVEs: What Is Unpatched — and What Will Never Be Patched

By Scott Bissett  ·  Published: August 12, 2026  ·  EOL Watch — security analysis  ·  CVE status verified against the live CISA KEV catalog (version 2026.08.11) and Broadcom advisories on August 12, 2026; lifecycle dates from our tracked data — methodology

If you searched "ESXi 6.5 CVE" or "ESXi 6.7 CVE," you are probably looking for a list of vulnerabilities to patch. Here is the honest version of that answer: on end-of-life ESXi, the CVE list is not your problem — the patch pipeline is. ESXi 6.5 and 6.7 both reached end of general support on October 15, 2022, and Broadcom's security advisories stopped evaluating them entirely. ESXi 7.0 is one step behind on the same road — past end of general support since October 2, 2025, and already carrying an actively-exploited, ransomware-abused vulnerability that Broadcom's own advisory matrix marks, in its own words, "No Patch Planned."

The pattern across the whole product line reduces to one sentence: the version you run determines whether a patch exists. ESXi 8.0 got the fix. ESXi 7.0 was told in writing it never would. ESXi 6.5 and 6.7 stopped even appearing in the advisories. This article walks that ladder rung by rung — every CISA-KEV-listed ESXi CVE verified against the live catalog, the ESXiArgs campaign that proved mass exploitation of old ESXi at scale, and the decision the dates force.

The short answer by version: ESXi 8.0 — supported, received fixes for every KEV-listed CVE, including CVE-2024-37085 (fixed in 8.0 Update 3). ESXi 7.0 — affected by CVE-2024-37085 with "No Patch Planned" per Broadcom advisory VMSA-2024-0013, and past end of general support since October 2, 2025. ESXi 6.5 / 6.7 — end of general support October 15, 2022; every patch that exists predates that window, and no CVE disclosed since is evaluated for them at all. The 2023 ESXiArgs ransomware wave — 3,800+ compromised hosts — showed what that population looks like to attackers.

The 7.0 problem: an exploited CVE with "No Patch Planned" in the vendor's own matrix

CVE-2024-37085 is an authentication bypass in ESXi's Active Directory integration: a member of a domain group named ESX Admins gains full administrative access to the host. An attacker who can create or rename an AD group — or re-create one that was deleted — walks onto the hypervisor with full control. It was exploited in the wild by ransomware operators including Akira and Black Basta, and CISA added it to the Known Exploited Vulnerabilities catalog on July 30, 2024, with a federal remediation deadline of August 20, 2024. Broadcom (as CNA) scores it 6.8; NVD rates it 7.2 — another reminder that KEV listing, not CVSS, is the exploitation signal that matters.

The part that makes this CVE the centerpiece of any ESXi lifecycle discussion is in Broadcom's advisory VMSA-2024-0013. The response matrix lists ESXi 8.0 and 7.0 as affected. For 8.0, the fixed version is ESXi 8.0 Update 3 (build ESXi80U3-24022510). For 7.0, the fixed-version column reads "No Patch Planned." Not "patch pending," not "contact support" — a written statement that the 7.0 train would never receive a patched build, made while 7.0 was still inside its general-support window. The only mitigation offered for 7.0 is a manual Active Directory reconfiguration workaround. Then, on October 2, 2025, ESXi 7.0 reached end of general support — converting "No Patch Planned" from a vendor decision into a permanent condition. That is why this CVE sits in our Exploited & Unpatchable feed with ESXi 7.0 as a permanently vulnerable version.

Why "No Patch Planned" matters more than any CVSS score: an unsupported version usually fails silently — no advisory mentions it, and you infer your exposure. ESXi 7.0 is the rarer, clearer case: the vendor named the version as affected by a KEV-listed, ransomware-exploited vulnerability and stated in writing that no fix would ship. There is no ambiguity to hide behind. A 7.0 host with AD integration enabled is exploitable by a published, actively-used technique, and the remediation options are: apply the AD workaround, upgrade, or accept it.
Running VMware ESXi past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers VMware ESXi is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Every KEV-listed ESXi CVE — and where a patch exists

We verified the following against the live CISA KEV catalog (version 2026.08.11, checked August 12, 2026). Six catalog entries name ESXi. Where a fixed build exists, its version tells you the story: fixes land only where the lifecycle clock is still running.

CVEWhat it isKEV addedFixed inStatus on 6.5 / 6.7 / 7.0
CVE-2025-22224VMCI TOCTOU race condition → out-of-bounds write; code execution on the host from inside a VM (CVSS 9.3, per VMSA-2025-0004)Mar 4, 20257.0 U3s, 8.0 U2d, 8.0 U3d7.0 patched (still supported at the time); 6.x absent from the advisory matrix
CVE-2025-22225Arbitrary kernel write → sandbox escape (CVSS 8.2, VMSA-2025-0004)Mar 4, 20257.0 U3s, 8.0 U2d, 8.0 U3dSame as above
CVE-2025-22226HGFS out-of-bounds read → information disclosure from the VMX process (CVSS 7.1, VMSA-2025-0004)Mar 4, 20257.0 U3s, 8.0 U2d, 8.0 U3dSame as above
CVE-2024-37085Active Directory ESX Admins authentication bypass; ransomware-exploited (Akira, Black Basta) (VMSA-2024-0013)Jul 30, 20248.0 U3 only7.0: No Patch Planned — Broadcom's words; 6.x not evaluated
CVE-2020-3992OpenSLP use-after-free → remote code execution via port 427 (CVSS 9.8, VMSA-2020-0023)Nov 3, 20217.0.1, ESXi670-202010401-SG, ESXi650-202010401-SGPatches exist for 6.5/6.7 — shipped in 2020, while both were supported
CVE-2019-5544OpenSLP heap overwrite → remote code execution via port 427 (CVSS 9.8, VMSA-2019-0022)Nov 3, 2021ESXi670-201912001, ESXi650-201912001, ESXi600-201912001Patches exist for 6.0/6.5/6.7 — shipped in 2019, while supported

Read the fourth column top to bottom and the lifecycle pattern is unmistakable. The 2019 and 2020 CVEs have 6.5 and 6.7 builds because 6.x was still supported when they were disclosed. By 2024, the matrix had shrunk to 8.0-and-7.0, with 7.0 already being told no. By 2025, the matrix covered 7.0 and 8.0 only — 6.x doesn't appear as "affected" or "not affected"; it simply isn't evaluated. An absent row is not a clean bill of health. It means the vendor has stopped testing that version against new vulnerabilities, which is precisely the condition our CVE blind spot coverage describes: scanners see no CVEs against EOL versions because no one is filing them, not because none exist.

ESXiArgs: the proof that EOL ESXi gets exploited at scale

One vulnerability belongs in this article precisely because it is not in the KEV catalog — and we want to be exact about that distinction. CVE-2021-21974 is a heap overflow in ESXi's bundled OpenSLP service, reachable by anyone on the network segment with access to port 427, allowing remote code execution. It carries a CVSS score of 8.8 and was patched in February 2021 via VMSA-2021-0002 — fixed builds ESXi 7.0 U1c, ESXi670-202102401-SG for 6.7, and ESXi650-202102101-SG for 6.5. As of our verification pass on August 12, 2026, it does not appear in CISA's KEV catalog. That is a catalog-inclusion quirk, not an exploitation verdict — because what happened next is a matter of public record.

In February 2023 — two years after the patch shipped — the ESXiArgs ransomware campaign swept the internet-reachable ESXi population, encrypting VM configuration files on over 3,800 servers worldwide, per the joint CISA/FBI advisory AA23-039A. The event was severe enough that CISA published a dedicated recovery script (cisagov/ESXiArgs-Recover) to help victims reconstruct encrypted VMs. The compromised population was, by definition, machines that had not applied a two-year-old patch — and by February 2023, ESXi 6.5 and 6.7 had been past end of general support for months. ESXiArgs is the empirical answer to "who would even bother attacking my old hypervisor?": attackers scanned the entire internet for one old CVE on one product and monetized every hit they found, in bulk, over a weekend.

The lesson compounds with the previous section. For CVE-2021-21974 a patch existed and thousands of operators hadn't applied it. For everything disclosed after a version's end of support, there is no patch to apply — the ESXiArgs scenario, minus the option of having patched.

Every ESXi version's dates

All dates from our tracked ESXi lifecycle data, current as of the verification pass on August 12, 2026. VMware lifecycles have two milestones: end of general support (the end of security patches and bug fixes) and end of technical guidance (a self-help period afterward — guidance only, no new patches). Each version links to its lifecycle page with live status and risk score.

VersionStatusReleasedEnd of general supportEnd of technical guidance
ESXi 9.1SupportedMay 12, 2026Aug 12, 2028Aug 12, 2029
ESXi 9.0SupportedJun 17, 2025Sep 17, 2027Sep 17, 2028
ESXi 8.0SupportedOct 11, 2022Oct 11, 2027Oct 11, 2029
ESXi 7.0EOLApr 2, 2020Oct 2, 2025Apr 2, 2027
ESXi 6.7EOLApr 17, 2018Oct 15, 2022Nov 15, 2023
ESXi 6.5EOLNov 15, 2016Oct 15, 2022Nov 15, 2023
ESXi 6.0EOLMar 12, 2015Mar 12, 2020Mar 12, 2022

Our mirrored dates are re-verified nightly against the upstream endoflife.date dataset, whose cited sources trace to Broadcom's product lifecycle page. Note that ESXi 7.0 is currently inside its technical-guidance window (to April 2, 2027) — a phase that provides guidance only, not patches; the "No Patch Planned" entry for CVE-2024-37085 was written while 7.0 was still in general support. For the full version-by-version dates story, see our VMware ESXi end-of-life dates article — this page covers the CVE exposure side; that one covers the calendar.

The decision: 8.0, 9.x, or off the platform

For anyone on 6.5, 6.7, or 7.0, "harden and stay" is not a real branch — CVE-2024-37085 has no fix on 7.0 by the vendor's own statement, and 6.x is no longer evaluated at all. The real decision is the landing zone, and the dates above complicate it more than most upgrade guides admit:

ESXi 8.0 — the established target with a short runway. Released October 2022, it is the mature choice and the version that actually received the CVE-2024-37085 fix (land on 8.0 Update 3 or later). But its end of general support is October 11, 2027 — roughly 14 months out from this article. An upgrade project that takes two quarters to plan and execute would land you on a train with about a year of patches left. If you choose 8.0, schedule the 9.x move in the same planning document.

ESXi 9.x — the current trains, on visibly shorter clocks. ESXi 9.0 runs to September 17, 2027 — earlier than 8.0's date — and 9.1 to August 12, 2028. Compare that to the six years ESXi 6.5 got, and the shape of the Broadcom era is clear: support windows on this platform are shorter than the ones your last upgrade cycle was planned around. The broader packaging and licensing shifts under Broadcom are their own subject — covered in our VMware Cloud Foundation article — but the lifecycle math alone means upgrading ESXi is no longer a once-every-six-years event.

Migrating off — the only branch that ends the recurrence. For some estates, the honest response to a 7.0-or-6.x position in 2026 is not another ESXi version but a platform decision. That is a larger project than an in-place upgrade, and this article won't pretend to size it for you — but it is the only option that doesn't put the same decision back on your calendar in 24 months. Whatever the platform, the underlying dynamic is the same everywhere: end of life is inevitable, and the only variable you control is whether you meet it on a schedule you chose.

We track VMware ESXi and 480+ other products against vendor-verified datesevery ESXi version with live status, check any version in seconds, or see what else hits end of life this quarter.

What to do about it

VMware ESXi currently carries an EOL Risk Score™ of 40/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the VMware ESXi lifecycle page.

The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination. And if this deadline feels like vendor caprice, it isn’t — why end of life is inevitable for every version, with the receipts.

Frequently Asked Questions

Which VMware ESXi CVEs are in CISA's Known Exploited Vulnerabilities catalog?

Six, verified against the live KEV catalog (version 2026.08.11): CVE-2025-22224 (VMCI TOCTOU race condition), CVE-2025-22225 (arbitrary kernel write), and CVE-2025-22226 (HGFS information disclosure), all added March 4, 2025; CVE-2024-37085 (Active Directory "ESX Admins" authentication bypass), added July 30, 2024; and two OpenSLP remote-code-execution flaws added November 3, 2021 — CVE-2020-3992 (use-after-free) and CVE-2019-5544 (heap overflow). Notably, CVE-2021-21974 — the vulnerability behind the 2023 ESXiArgs ransomware wave — is not in the KEV catalog.

Can ESXi 7.0 be patched for CVE-2024-37085?

No, and Broadcom has said so in writing. Advisory VMSA-2024-0013 lists ESXi 7.0 as affected by CVE-2024-37085 with the fixed-version column reading "No Patch Planned" — the fix shipped only in ESXi 8.0 Update 3. The only mitigation for 7.0 is a manual Active Directory reconfiguration workaround. ESXi 7.0 then reached end of general support on October 2, 2025, so no update will ever come. This CVE is KEV-listed and has been exploited by ransomware operators including Akira and Black Basta.

Is ESXi 6.5 or 6.7 still receiving security patches?

No. Both ESXi 6.5 and 6.7 reached end of general support on October 15, 2022, and end of technical guidance on November 15, 2023, per our tracked lifecycle data. Every KEV-listed CVE that affects 6.5 or 6.7 has a fixed build only because it was disclosed while those versions were still supported — the last of those patch pipelines closed years ago. Broadcom advisories no longer evaluate 6.x at all: the response matrices in VMSA-2024-0013 and VMSA-2025-0004 cover only 7.0 and later. A quiet CVE list for ESXi 6.x means nobody is looking, not that nothing is wrong.

Was CVE-2021-21974 (ESXiArgs) ever exploited at scale, and is it in the KEV catalog?

It was exploited at scale — and it is not in the KEV catalog, a distinction worth knowing. CVE-2021-21974 is an OpenSLP heap-overflow allowing remote code execution via port 427, patched in February 2021 (ESXi 7.0 U1c, ESXi670-202102401-SG, ESXi650-202102101-SG per VMSA-2021-0002). In February 2023 the ESXiArgs ransomware campaign compromised over 3,800 ESXi servers worldwide by exploiting it, prompting a joint CISA/FBI recovery advisory (AA23-039A) and a CISA-published recovery script. By that point ESXi 6.5 and 6.7 had been past end of general support for months. As of our verification on August 12, 2026, CVE-2021-21974 does not appear in CISA's KEV catalog.

Which ESXi version should I move to from 6.x or 7.0?

Per our tracked lifecycle data: ESXi 8.0 (released October 2022) is the established target and the only version that received the CVE-2024-37085 fix (land on 8.0 Update 3 or later), but its end of general support is October 11, 2027 — about 14 months of runway from this article's publication. ESXi 9.0 runs to September 17, 2027 and 9.1 to August 12, 2028; Broadcom's newer release cycles are notably shorter than the roughly five-to-seven-year windows 6.x enjoyed. Whichever you choose, plan the next upgrade at the same time — or evaluate migrating off the platform entirely, which is a larger project but the only branch that ends the recurring decision.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)