VMware has patched three actively exploited zero-day vulnerabilities affecting its ESXi, Workstation, and Fusion products. Tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, these flaws allow attackers with administrative or root privileges to break out of the virtual machine sandbox, potentially compromising the underlying host system.