Broadcom Shares Plunge on Major VMware Security Threat
Broadcom shares (AVGO) fell about 6% after reports that attackers are exploiting a recently patched VMware vCenter Syslog Server vulnerability. Broadcom said the issue disclosed July 29 could let a network-access attacker run unauthorized code. A report cited reverse SSH tool installs and 361 affected IPs in 47 countries, with Quirso noting attacker communications starting Aug. 3.
How this was made

The 30-second read
Why it matters
New reporting claims active exploitation after the patch, including a reverse SSH tool and identified victim IPs, increasing perceived operational and reputational risk for Broadcom’s VMware platform.
Market read
The stock move is attributed to fresh exploit evidence and expanding incident details, which can drive continued volatility in AVGO until remediation and scope are clarified.
What to watch
The article does not quantify Broadcom’s financial exposure, customer churn risk, or whether the exploit is limited to misconfigured or unpatched systems.
Background
Broadcom disclosed a critical VMware vCenter Syslog Server vulnerability on July 29 and issued an emergency patch.
Ticker impact
Broadcom shares fell about 6% after reports said attackers are exploiting a recently fixed VMware vCenter Syslog Server flaw.
Bearish bias for the next several sessions, with volatility elevated until more details on affected customers and remediation emerge.
The article ties the stock drop directly to new exploit activity (reverse SSH tool, victim IPs, post-patch communications) rather than only the original disclosure.
Market effects
Highlights ongoing enterprise software security risk and potential reputational and support-cost pressure for virtualization vendors.
No clear regional demand impact stated; victim IPs span multiple countries.
Cross-border attacker infrastructure and multi-country affected IPs suggest broad enterprise exposure, not localized to one geography.
Counterpoint
If the emergency patch is effective for most environments, the incremental impact may fade quickly after initial panic and remediation updates.
Key entities
- productVMware vCenter Syslog Server
A VMware tool used to manage and oversee virtual infrastructure, implicated in the critical vulnerability.
- companyQuirso
Digital forensics firm that reported post-patch communications to attacker-controlled infrastructure and identified victim IPs.



