Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

VMware

Vulnerabilities in VMware vCenter Server, ESXi, and the Spring Framework VMware stewards — virtualization and application infrastructure whose compromise can mean full control of an organization's entire virtual estate.

26 CVEs6 articlesRSS
CVEs
CVE-2025-22224
[ CRITICAL ]CVSS 9.3EPSS 1.6%kev

VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

VMware / ESXi and Workstation
CVE-2025-22225
[ HIGH ]CVSS 8.2EPSS 1.0%kev

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

VMware / ESXi
CVE-2025-22226
[ HIGH ]CVSS 7.1EPSS 1.7%kev

VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

VMware / ESXi, Workstation, and Fusion
CVE-2024-38812
[ CRITICAL ]CVSS 9.8EPSS 54.6%kev

VMware vCenter Server Heap-Based Buffer Overflow Vulnerability

VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter Server to execute remote code by sending a specially crafted packet.

VMware / vCenter Server
CVE-2024-38813
[ HIGH ]CVSS 7.5EPSS 17.4%kev

VMware vCenter Server Privilege Escalation Vulnerability

VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by sending a specially crafted packet.

VMware / vCenter Server
CVE-2024-37085
[ MEDIUM ]CVSS 6.8EPSS 26.0%kev

VMware ESXi Authentication Bypass Vulnerability

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

VMware / ESXi
CVE-2022-22948
[ MEDIUM ]CVSS 6.5EPSS 13.8%kev

VMware vCenter Server Incorrect Default File Permissions Vulnerability

VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.

VMware / vCenter Server
CVE-2023-34048
[ CRITICAL ]CVSS 9.8EPSS 99.4%kev

VMware vCenter Server Out-of-Bounds Write Vulnerability

VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol that allows an attacker to conduct remote code execution.

VMware / vCenter Server
CVE-2023-20867
[ LOW ]CVSS 3.9EPSS 13.5%kev

VMware Tools Authentication Bypass Vulnerability

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.

VMware / Tools
CVE-2023-20887
[ CRITICAL ]CVSS 9.8EPSS 98.3%kev

Vmware Aria Operations for Networks Command Injection Vulnerability

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.

VMware / Aria Operations for Networks
CVE-2022-22947
[ CRITICAL ]CVSS 10.0EPSS 98.3%kev

VMware Spring Cloud Gateway Code Injection Vulnerability

Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.

VMware / Spring Cloud Gateway
CVE-2022-22960
[ HIGH ]CVSS 7.8EPSS 35.8%kev

VMware Multiple Products Privilege Escalation Vulnerability

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.

VMware / Multiple Products
CVE-2022-22954
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.

VMware / Workspace ONE Access and Identity Manager
CVE-2022-22965
[ CRITICAL ]CVSS 9.8EPSS 99.7%kev

Spring4Shell — Spring Framework Remote Code Execution

A remote-code-execution vulnerability in the Spring Framework, stewarded by VMware, allows an attacker to achieve RCE via data binding under specific conditions — JDK 9+, Spring Framework versions before 5.3.18 / 5.2.20, and deployment as a traditional WAR on Apache Tomcat.

VMware / Spring Framework
CVE-2018-6961
[ HIGH ]CVSS 8.1EPSS 86.4%kev

VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

VMware / SD-WAN Edge
CVE-2021-21973
[ MEDIUM ]CVSS 5.3EPSS 87.6%kev

VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

VMware / vCenter Server and Cloud Foundation
CVE-2021-21975
[ HIGH ]CVSS 7.5EPSS 78.3%kev

VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

VMware / vRealize Operations Manager API
CVE-2021-22017
[ MEDIUM ]CVSS 5.3EPSS 49.2%kev

VMware vCenter Server Improper Access Control

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

VMware / vCenter Server
CVE-2019-5544
[ CRITICAL ]CVSS 9.8EPSS 96.8%kev

VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability

VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.

VMware / VMware ESXi and Horizon DaaS
CVE-2020-3950
[ HIGH ]CVSS 7.8EPSS 7.3%kev

VMware Multiple Products Privilege Escalation Vulnerability

VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.

VMware / Multiple Products
CVE-2020-3952
[ CRITICAL ]CVSS 9.8EPSS 90.4%kev

VMware vCenter Server Information Disclosure Vulnerability

VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.

VMware / vCenter Server
CVE-2020-3992
[ CRITICAL ]CVSS 9.8EPSS 83.0%kev

VMware ESXi OpenSLP Use-After-Free Vulnerability

VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.

VMware / ESXi
CVE-2020-4006
[ CRITICAL ]CVSS 9.1EPSS 23.8%kev

Multiple VMware Products Command Injection Vulnerability

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.

VMware / Multiple Products
CVE-2021-21985
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

VMware vCenter Server Improper Input Validation Vulnerability

VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.

VMware / vCenter Server
CVE-2021-22005
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

VMware vCenter Server File Upload Vulnerability

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

VMware / vCenter Server
CVE-2021-21972
[ CRITICAL ]CVSS 9.8EPSS 99.5%kev

VMware vCenter Server vSphere Client Remote Code Execution

A remote-code-execution vulnerability in the vSphere Client (HTML5) plugin for VMware vCenter Server allows an unauthenticated attacker with network access to port 443 to upload a malicious file and execute arbitrary commands with unrestricted privileges on the underlying operating system.

VMware / vCenter Server
Articles
~/articles/2026-08-13-vcenter-cve-2026-59310-reverse-ssh-persistence
VMware vCenter Exploit Deploys Reverse SSH Backdoor
● Breaking
vmware

VMware vCenter Exploit Deploys Reverse SSH Backdoor

Threat actors exploiting CVE-2026-59310 are deploying a reverse SSH tool for persistent access on compromised vCenter management planes.

read →
~/articles/2026-08-12-vcenter-cve-2026-59310-exploited-in-wild
vCenter Auth Bypass CVE-2026-59310 Now Exploited
vmware

vCenter Auth Bypass CVE-2026-59310 Now Exploited

CVE-2026-59310 exploitation confirmed in VMware vCenter Server. CVSS 9.8. Patches out since July 29 — unpatched instances need isolation now.

read →
~/articles/2026-07-31-vmware-vcenter-esxi-critical-auth-bypass-vm-escape-patch
Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape
vmware

Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape

Broadcom patched five CVEs in VMware vCenter, ESXi, Workstation, and Fusion. Three are critical: auth bypass, RCE, VM escape. Patch vCenter now.

read →
~/articles/2026-07-29-broadcom-vmware-vcenter-esx-critical-patches
Broadcom Patches Critical VMware Auth Bypass, RCE, VM Escape
vmware

Broadcom Patches Critical VMware Auth Bypass, RCE, VM Escape

Broadcom shipped security updates for VMware vCenter, ESX, Workstation, and Fusion covering three critical flaws including a CVSS 9.8 no-auth bypass. Patch now.

read →
~/articles/2026-07-04-vmware-vcenter-vsphere-client-rce-cve-2021-21972
vCenter's Upload Bug: Don't Expose Management Planes
Explainer
vmware

vCenter's Upload Bug: Don't Expose Management Planes

CVE-2021-21972 let unauthenticated attackers execute code with root privileges on VMware vCenter Server — and internet scans found tens of thousands of instances exposed anyway, against VMware's own guidance.

read →
~/articles/2026-07-04-spring4shell-vmware-spring-framework-rce
Spring4Shell: Why This One Needed Careful Triage, Not Panic
Explainer
vmware

Spring4Shell: Why This One Needed Careful Triage, Not Panic

CVE-2022-22965 leaked publicly before VMware's patch was ready — but unlike Log4Shell, exploitation required a specific combination of conditions that made blanket panic the wrong response.

read →