ESXi 7.0
ESXi-7.0
Os Release
· ESXi Series
Is ESXi 7.0 still maintained?
No. VMware (Broadcom) no longer maintains ESXi 7.0; support ended 2025-10-02. It receives no fixes of any kind, including security patches. Devices running it are unpatched against any newer vulnerability — plan an upgrade to a maintained release. See VMware (Broadcom)'s lifecycle bulletin.
When do security fixes for ESXi 7.0 stop?
Engineering fixes for ESXi 7.0 — including security patches — stop on 2025-10-02. After that date, a device on this release cannot be patched against newly disclosed vulnerabilities without upgrading, which is the point that matters for KEV exposure and compliance.
What should I upgrade ESXi 7.0 to?
Upgrade to a currently maintained VMware (Broadcom) release. Check the release-train table on the vendor page for the nearest supported version.
What known-exploited CVEs apply to the ESXi 7.0 past end of support?
6 CVEs in CISA's Known Exploited Vulnerabilities catalog affect VMware (Broadcom) ESXi. Because ESXi 7.0 is past end of engineering, it will not receive fixes for them — a device left on this release is exploitable with no patch available. Upgrade to a maintained release. See the Known Exploited Vulnerabilities table below for the full list.
Known Exploited Vulnerabilities
This device is past VMware (Broadcom)'s security-support date. 6 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. VMware (Broadcom) is not issuing patches for this model. Isolate, compensate, or refresh.
| CVE | KEV added | Vulnerability | Flags |
|---|---|---|---|
CVE-2025-22226
|
VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability | ||
CVE-2025-22225
|
VMware ESXi Arbitrary Write Vulnerability | Ransomware | |
CVE-2025-22224
|
VMware ESXi and Workstation TOCTOU Race Condition Vulnerability | ||
CVE-2024-37085
|
VMware ESXi Authentication Bypass Vulnerability | Ransomware | |
CVE-2019-5544
|
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability | Ransomware | |
CVE-2020-3992
|
VMware ESXi OpenSLP Use-After-Free Vulnerability | Ransomware |
Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.
Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.
ESXi 7.0 Release Lifecycle
ESXi 7.0 is a VMware (Broadcom) ESXi software release. Releases are maintained on a fixed schedule: VMware (Broadcom) ships fixes and security patches until the release reaches end of engineering, after which a device must be upgraded to a maintained release to stay patchable. The dates below are milestones for the software train, not for any specific appliance — hardware running this release has its own separate lifecycle. This product has reached end of life as of , meaning VMware (Broadcom) no longer provides technical support, software updates, or hardware replacement for this product. Organizations still running the ESXi 7.0 should plan a migration .
Lifecycle Milestones
| Lifecycle notice published | 6y 4mo ago | |
|---|---|---|
| End of software maintenance | 10mo ago | |
| End of security vulnerability support | 10mo ago | |
| Last date of support | 10mo ago |
Additional Dates
| Ga Date | 6y 4mo ago |
|---|