Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Broadcom

Broadcom Vendor Cyber Rating & Cyber Score

broadcom.com

Broadcom provides semiconductors and infrastructure software for global organizations’ complex, mission-critical needs. We combine long-term R&D investment with superb execution to deliver the best technology, at scale. Through focus and expertise, Broadcom sets the standard in industries where technology breakthroughs shape markets. Our semiconductor and semiconductor-based solutions serve markets across networking connectivity, wireless device connectivity, servers and storage systems, broadband, and industrial. Broadcom’s infrastructure software solutions serve markets including private cloud, mainframe software, cybersecurity, enterprise software, and Fibre Channel storage area network management. With these core technologies, we help


Broadcom A.I CyberSecurity Scoring

Broadcom
Company Information
Website:http://www.broadcom.com
Employees number:55,707
Number of followers:616,560
NAICS:3344
Industry Type:Semiconductor Manufacturing
Homepage:broadcom.com
Broadcom Risk Score (AI oriented)
Between 750 and 799
logo
BroadcomSemiconductor Manufacturing
Updated:
19/05/2026
760/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Broadcom Global Score (TPRM)
xxxx
logo
BroadcomSemiconductor Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Broadcom
BroadcomFair
Current Score
760Baa (FAIR)
01000
8 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
760Before Incident
MAY 2026
759Before Incident
APRIL 2026
756Before Incident
MARCH 2026
757Before Incident
Vulnerability
30 Mar 2026Broadcom
Broadcom: Symantec DLP Agent Flaw Exposed Systems to Privilege Escalation Attacks

High-Severity Symantec DLP Agent Flaw Grants SYSTEM Privileges to Attackers

756After Incident
CRITICAL-1
BRO1775111316
High-Severity Symantec DLP Agent Flaw Grants SYSTEM Privileges to Attackers A critical local privilege escalation (LPE) vulnerability in the Symantec Data Loss Prevention (DLP) Agent for Windows (CVE-2026-3991, CVSS 7.8) allows low-privileged attackers to gain full SYSTEM-level control of affected machines. Discovered by security researcher Manuel Feifel and reported to Broadcom in late 2025, the flaw stems from a hardcoded file path in the agent’s OpenSSL integration, enabling attackers to bypass security controls. ### Exploitation Mechanism The vulnerability arises from the edpa.exe process, which runs with SYSTEM privileges and attempts to load an OpenSSL configuration file from a non-existent directory: `C:\VontuDev\workDir\openssl\output\x64\Release\SSL\openssl.cnf`. Since the `C:\VontuDev` folder does not exist by default, attackers can create it and place a malicious OpenSSL configuration file and DLL in the path. When the DLP Agent restarts, it loads these files, executing the attacker’s code with SYSTEM rights effectively granting full control. This technique is particularly stealthy, as the malicious payload runs within the trusted DLP agent process, evading endpoint security and monitoring tools. ### Affected Versions & Patch Availability The flaw impacts Symantec DLP Agent versions prior to 16.1 MP2 and 25.1 MP1. Broadcom released patches on March 30, 2026, with the following fixed versions: - DLP 25.1 MP1 - DLP 16.1 MP2 - DLP 16.0 RU2 HF9 - DLP 16.0 RU1 MP1 HF12 - DLP 16.0 MP2 HF15 No additional configuration changes are required applying the update fully mitigates the vulnerability. ### Impact & Risk While exploitation requires an attacker to already have basic access to a target system, privilege escalation is a key tactic in ransomware and cyber espionage campaigns. The flaw’s ability to bypass security controls and persist undetected makes it a significant threat to organizations relying on Symantec DLP for data protection.
INCIDENT DETAILS -
TYPE
Local Privilege Escalation (LPE)
IMPACT
Systems Affected: Windows machines running vulnerable Symantec DLP Agent versionsOperational Impact: Full SYSTEM-level control of affected machines, potential for ransomware or cyber espionageBrand Reputation Impact: Potential reputational damage due to security flaw in data protection software
MARCH 2026
761Before Incident
Cyber Attack
17 Mar 2026Broadcom
Estée Lauder, Broadcom, Abbott Technologies, Oracle and Bechtel: Silence from the Corporate Giants: Four Companies Yet to Comment on Oracle EBS Hack

Oracle E-Business Suite Hack Leaves Four Major Companies Silent on Impact

756After Incident
CRITICAL-5
BROBECTHEORAABB1773750615
Oracle E-Business Suite Hack Leaves Four Major Companies Silent on Impact A recent cyberattack targeting Oracle E-Business Suite (EBS) has disrupted organizations reliant on the platform for critical business operations, including finance, supply chain, HR, and procurement. While many companies have responded with public disclosures and mitigation efforts, Broadcom, Bechtel, Estée Lauder, and Abbott Technologies have yet to issue any statements, raising concerns about transparency and crisis management. The breach exposes vulnerabilities in a widely used enterprise software suite, threatening the integrity of sensitive corporate and customer data. Security researchers and incident response teams are assessing the full scope of the compromise, with affected organizations working to determine exposure and prevent follow-on attacks. In contrast to the silent four, other companies have taken proactive steps, including acknowledging the breach, implementing security measures, collaborating with cybersecurity firms, and notifying stakeholders. This approach is considered best practice in handling enterprise-wide software vulnerabilities. The continued silence from Broadcom, Bechtel, Estée Lauder, and Abbott Technologies leaves stakeholders uninformed about potential risks, data protection efforts, and the companies’ cybersecurity commitments. The lack of disclosure may also invite regulatory scrutiny, particularly for publicly traded firms, while risking long-term reputational damage. As cybersecurity incidents grow in frequency and severity, transparent communication is increasingly seen as a corporate obligation both for stakeholder trust and legal compliance. The absence of updates from these four companies underscores a critical gap in modern incident response policies.
INCIDENT DETAILS -
TYPE
Cyberattack
IMPACT
Data Compromised: Sensitive corporate and customer dataSystems Affected: Finance, supply chain, HR, and procurement systemsOperational Impact: Disruption of critical business operationsBrand Reputation Impact: Potential long-term reputational damage
DATA BREACH
Type Of Data Compromised: Sensitive corporate and customer dataSensitivity Of Data: High
FEBRUARY 2026
758Before Incident
JANUARY 2026
757Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
747Before Incident
AUGUST 2025
744Before Incident
JULY 2025
741Before Incident
JUNE 2025
787Before Incident
Ransomware
16 Jun 2025Broadcom
Broadcom

Cl0p Exploits Zero-Day Vulnerabilities in Oracle E-Business Suite Leading to Massive Data Breaches

736After Incident
CRITICAL-51
BRO3105131112625
Broadcom, a global technology leader valued at hundreds of billions, was among the high-profile victims of Cl0p’s ransomware attack exploiting a zero-day vulnerability in Oracle’s E-Business Suite (CVE-2025-61882 and CVE-2025-21884). The cybercriminal group exfiltrated sensitive corporate and customer data, threatening to leak or sell it unless a ransom was paid. The breach compromised critical systems, risking financial records, proprietary business data, and third-party customer information. Cl0p’s extortion tactics included warnings of public disclosure on their blog, torrent leaks, or sales to malicious actors, amplifying reputational and operational risks. Given Broadcom’s role in semiconductor and infrastructure technology, the attack posed supply chain cascading risks, potentially disrupting clients reliant on its products. Oracle issued emergency patches, but the damage—including data theft, potential regulatory fines, and erosion of stakeholder trust—had already occurred. The incident underscores vulnerabilities in enterprise software dependencies, with Broadcom facing long-term financial and strategic repercussions if the stolen data is weaponized.
INCIDENT DETAILS -
TYPE
RansomwareData BreachZero-Day Exploit
MOTIVATION
Financial Gain (Ransomware Extortion)
IMPACT
Oracle E-Business Suite (EBS) versions 12.2.3–12.2.14Operational Impact: Significant (data exfiltration, potential system compromise)Brand Reputation Impact: High (public disclosure of breaches, ransom demands)Identity Theft Risk: High (PII and sensitive corporate data exfiltrated)
DATA BREACH
Corporate DataCustomer DataSensitive Business InformationSensitivity Of Data: High
MAY 2025
823Before Incident
Ransomware
01 May 2025Broadcom
Broadcom

Cl0p Ransomware Gang Claims Breach of Broadcom via Zero-Day in Oracle E-Business Suite

785After Incident
CRITICAL-38
BRO0893008112125
The Cl0p ransomware gang breached Broadcom, a $300+ billion semiconductor and infrastructure software leader, by exploiting an unpatched zero-day vulnerability in Oracle E-Business Suite. This ERP platform manages critical operations, including supply chain, financial systems, and customer data, making it a high-value target. The attackers likely exfiltrated sensitive corporate data (potentially including intellectual property, manufacturing secrets, and customer information) before deploying ransomware, following Cl0p’s typical double-extortion tactic. The breach risks operational disruptions in global manufacturing, regulatory penalties for data exposure, and reputational damage due to the involvement of a notorious ransomware group. The use of a zero-day exploit amplifies the threat, as other organizations using Oracle E-Business Suite may face similar attacks until a patch is released. Broadcom has not confirmed the incident, but the alleged compromise aligns with Cl0p’s pattern of targeting high-value enterprises via unpatched vulnerabilities in widely used software.
INCIDENT DETAILS -
TYPE
ransomwaredata breachzero-day exploit
MOTIVATION
financial gain (ransomware)data theft for extortiondisruption of high-value enterprise targets
IMPACT
Oracle E-Business Suitesupply chain operationsfinancial systemscustomer datamanufacturing operationsresearch datapotential disruption of manufacturing operationssupply chain interruptionsglobal infrastructure riskshigh (targeting a $300B+ company)potential loss of trust in supply chain securitypotential regulatory compliance violations (e.g., data protection laws)
DATA BREACH
potential: corporate data (supply chain, financial, customer)intellectual property (research data)high (enterprise resource planning data)potentially confidential (manufacturing, R&D)claimed by Cl0p (typical tactic before ransomware deployment)
SEPTEMBER 2024
845Before Incident
Ransomware
01 Sep 2024Broadcom
Broadcom

Ransomware Attack on Business Systems House (BSH) Leading to Broadcom Employee Data Theft

818After Incident
CRITICAL-27
BRO3362533111725
A ransomware attack targeted Business Systems House (BSH), a Middle Eastern payroll partner of ADP, in September 2024, leading to the theft of Broadcom’s employee data. The compromised data was leaked online in December 2024, but Broadcom was not notified until May 2025—an eight-month delay. The El Dorado ransomware group claimed responsibility, exploiting Broadcom’s ongoing transition between payroll providers. The breach exposed sensitive employee information, including personal and financial details, while Broadcom was still dependent on ADP and BSH for payroll processing. The incident underscores critical vulnerabilities in third-party supply chain security, particularly during vendor transitions, and highlights the prolonged risks of undetected data exfiltration in ransomware attacks. The delayed disclosure further exacerbated reputational and operational risks for Broadcom, a global semiconductor and infrastructure software leader.
INCIDENT DETAILS -
TYPE
ransomwaredata breachsupply chain attack
MOTIVATION
financial gaindata theft
IMPACT
Broadcom employee dataBrand Reputation Impact: negative (ripples through tech and cybersecurity community)Identity Theft Risk: potential (employee data exposed)
DATA BREACH
employee dataSensitivity Of Data: high (employee records)Data Exfiltration: yes (leaked online in December 2024)Personally Identifiable Information: likely (employee data)
JANUARY 2024
846Before Incident
Vulnerability
01 Jan 2024Broadcom
Broadcom: Cyber Security News ®’s Post

CISA Flags Actively Exploited VMware vCenter Server Vulnerability (CVE-2024-37079)

844After Incident
CRITICAL-2
BRO1769309760
CISA Flags Actively Exploited VMware vCenter Server Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-37079, a critical remote code execution (RCE) vulnerability in Broadcom’s VMware vCenter Server, to its Known Exploited Vulnerabilities (KEV) catalog. The move follows confirmed reports of active exploitation in the wild, heightening risks for enterprises using vCenter for virtualization management. The flaw allows attackers with network access to the vCenter Server to execute arbitrary code, potentially gaining full control over the system. No additional user interaction or privileges are required, making it a high-severity threat. Organizations running affected versions of vCenter are urged to prioritize patching, as exploitation could lead to unauthorized access, data breaches, or lateral movement within networks. VMware released patches for the vulnerability earlier this month, but the inclusion in CISA’s KEV catalog underscores its urgency. Federal agencies under CISA’s binding operational directive (BOD 22-01) must remediate the flaw by a specified deadline, though private sector entities are also advised to act swiftly. The incident highlights the growing targeting of virtualization infrastructure, a critical component in enterprise IT environments. Details on attack vectors and threat actors remain limited, but the vulnerability’s inclusion in the KEV catalog signals its immediate operational risk.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: VMware vCenter ServerOperational Impact: Unauthorized access, lateral movement within networks
JUNE 2023
847Before Incident
Vulnerability
16 Jun 2023Broadcom
Broadcom (VMware)

Broadcom Patches High-Severity VMware Aria Operations and VMware Tools Privilege Escalation Vulnerability (CVE-2025-41244) Exploited by UNC5174

846After Incident
CRITICAL-1
BRO4592445093025
Broadcom patched a high-severity privilege escalation vulnerability (CVE-2025-41244) in VMware Aria Operations and VMware Tools, actively exploited since October 2024 by UNC5174, a Chinese state-sponsored threat actor linked to China’s Ministry of State Security (MSS). The flaw allows an unprivileged local attacker to escalate privileges to root-level code execution by staging a malicious binary in paths like `/tmp/httpd` and exploiting VMware’s service discovery mechanism. UNC5174, known for selling network access to U.S. defense contractors, UK government entities, and Asian institutions, previously exploited CVE-2023-46747 (F5 BIG-IP), CVE-2024-1709 (ConnectWise ScreenConnect), and CVE-2025-31324 (SAP NetWeaver).The vulnerability poses a critical risk as it enables full system compromise, potentially allowing attackers to move laterally across networks, steal sensitive data, or deploy additional malware. While no direct data breach or ransomware was confirmed in this case, the exploitation by a state-backed APT group suggests espionage or pre-positioning for future attacks. Broadcom also patched two other high-severity VMware NSX flaws reported by the NSA, indicating a broader pattern of targeted cyber operations against enterprise infrastructure.
INCIDENT DETAILS -
TYPE
Privilege EscalationZero-Day Exploit
MOTIVATION
EspionageFinancial Gain (selling network access)Cyber Warfare
IMPACT
VMware Aria Operations (credential-based mode)VMware Tools (credential-less mode)Operational Impact: Potential root-level code execution on vulnerable VMs, leading to full system compromiseBrand Reputation Impact: High (zero-day exploitation by state-sponsored actor, multiple high-profile vulnerabilities in 2024)
JANUARY 2020
846Before Incident
Vulnerability
01 Jan 2020Broadcom
Microsoft, 7-Eleven, Cisco, NGINX and Broadcom: 7-Eleven - Security Affairs

Pwn2Own Berlin 2026 Highlights Major Exploits and Cyber Incidents

845After Incident
CRITICAL-1
BROMIC7-ENGICIS1779164825
Pwn2Own Berlin 2026 Highlights Major Exploits as Zero-Days and Breaches Surge The second and third days of Pwn2Own Berlin 2026 saw researchers earn $385,750 in bounties, pushing the event’s total payout to $1.298 million. Among the notable exploits, Microsoft Exchange Server was successfully compromised, contributing to the growing tally. DEVCORE was crowned "Master of Pwn" after demonstrating multiple high-impact vulnerabilities. In parallel, Chaotic Eclipse disclosed MiniPlasma, a zero-day in Windows, suggesting an incomplete or overlooked security fix from 2020. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft Exchange Server flaw and a Cisco Catalyst SD-WAN vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation risks. A critical 18-year-old flaw (CVE-2026-42945) in NGINX, the world’s most widely deployed web server, was also uncovered, with experts warning of ongoing attacks. Meanwhile, Grafana confirmed a GitHub token breach after a cybercrime group claimed responsibility, while ShinyHunters breached 7-Eleven, exposing franchisee data and Salesforce records. Additional incidents included: - A public Amazon S3 bucket leaking sensitive guest data from Japanese hotel platform Tabiq. - OpenAI suffering a supply chain attack via malicious TanStack packages. - Broadcom releasing a security update for a VMware Fusion root access bug. - The Ghostwriter group resuming cyberattacks on Ukrainian government targets. - Researchers identifying YellowKey and GreenPlasma, two new Windows zero-days. - A Linux Kernel bug (Fragnesia) enabling local root access attacks. - Attackers exploiting a Funnel Builder vulnerability to inject e-skimmers into e-commerce stores. The event underscored persistent threats across enterprise software, cloud services, and critical infrastructure, with zero-days and supply chain attacks remaining dominant vectors.
INCIDENT DETAILS -
TYPE
Zero-day ExploitData BreachSupply Chain AttackRansomware
MOTIVATION
Financial GainCyber EspionageData TheftDemonstration of Exploits
IMPACT
Financial Loss: $385,750 (bounties paid) + $1.298 million (total payout)GitHub tokensFranchisee dataSalesforce recordsGuest data (Tabiq)Personally Identifiable InformationMicrosoft Exchange ServerWindows OSNGINXCisco Catalyst SD-WANVMware FusionGrafana7-Eleven systemsOpenAI (via TanStack packages)E-commerce stores (via e-skimmers)Service DisruptionUnauthorized AccessData ExfiltrationGrafana7-ElevenOpenAITabiqHigh (PII exposed)High (e-skimmers injected)
DATA BREACH
GitHub TokensFranchisee DataSalesforce RecordsGuest DataPIIHighYes (ShinyHunters, Ghostwriter group)Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Broadcom ?
?
What was Broadcom's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Broadcom's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Broadcom's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Broadcom ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Broadcom's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?