CVE-2023-34048
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
8 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.21%
probability
This CVE has a 93.21% probability
of being exploited in the next 30 days.
0%
Top 99.8th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Broadcom fixes three VMware zero-days exploited in attacks
BleepingComputer
Mar 04, 2025
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Chinese hackers exploit VMware bug as zero-day for two years
BleepingComputer
Jan 19, 2024
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
Qualys
May 08, 2025
Security Advisory 2023-084
CERT-EU
Oct 27, 2023
Signal Intelligence
Confidence
92%
EPSS
93.21%
Mentions
8
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2023-34048 is explicitly named as a zero-day exploited in attacks by Broadcom's October 2023 security advisory. Article [1] directly states 'Broadcom fixes three VMware zero-days exploited in attacks,' and article [2] confirms Chinese hackers exploited this vulnerability as a zero-day for two years prior to the October 2023 patch, establishing clear in-the-wild exploitation before patch availability.
Threat Actors 11
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
Hacking Team
apt_group
🇮🇹 IT
Infy
apt_group
Information theft and espionage
🇮🇷 IR
GhostSec
apt_group
UNC3886
apt_group
Information theft and espionage
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Markopolo
apt_group
🇷🇺 RU
Big Panda
apt_group
🇨🇳 CN
Triage Info
Decided atMar 05, 2026