VMware vendor intelligence
VMware Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting VMware products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 39
- Known exploited vulnerabilities affecting VMware products
- In CISA KEV
- 34
- Records also listed in the official catalog
- Beyond CISA KEV
- 5
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- VMware KEVs with sensor-observed exploitation activity
The catalog gap matters for VMware exposure
Five of the 39 exploited VMware CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 13% of this vendor portfolio.
- 87%
- Covered by CISA
- 13%
- Beyond CISA
- 32
- Product families
Attested VMware CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-59310
vCenter directory-traversal vulnerability |
Cloud Foundation, vSphere Foundation, vCenter, Telco Cloud Infrastructure, Telco Cloud Platform | Confirmed | In CISA | 12 Aug 2026 |
|
CVE-2021-21983
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with... |
VMware vRealize Operations | High | Beyond CISA | 12 Aug 2026 |
|
CVE-2022-22956
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A... |
Workspace ONE Access | High | Beyond CISA | 05 Feb 2026 |
|
CVE-2021-22053
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within... |
Spring Cloud Netflix Hystrix Dashboard | High | Beyond CISA | 21 Aug 2025 |
|
CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.... |
Workspace ONE Access, Identity Manager, vRealize Automation | High | Beyond CISA | 31 Jul 2025 |
|
CVE-2021-22054
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37... |
Workspace ONE UEM | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-22719
VMware Aria Operations command injection vulnerability |
VMware Aria Operations, VMware Cloud Foundation Operations, Telco Cloud Platform, Telco Cloud Infrastructure | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to... |
vCenter Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-41244
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) |
VCF operations, VMware tools, VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-21978
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of... |
VMware View Planner | High | Beyond CISA | 22 Apr 2025 |
|
CVE-2020-4006
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware Identity Manager (vIDM), VMware Identity Manager Connector (vIDM Connector), VMware Cloud Foundation, vRealize Suite Lifecycle Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-21985
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in... |
VMware vCenter Server and VMware Cloud Foundation | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3952
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does... |
VMware vCenter Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22005
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3950
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before... |
VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3992
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a... |
VMware ESXi | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-5544
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the... |
ESXi and Horizon DaaS | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22017
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the... |
VMware vRealize Operations | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2021-21973
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2018-6961
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component... |
NSX SD-WAN by VeloCloud | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2020-5410
Directory Traversal with spring-cloud-config-server |
Spring Cloud Config | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific... |
Spring Framework | Confirmed | In CISA | 04 Apr 2022 |
|
CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious... |
VMware Workspace ONE Access and Identity Manager | Confirmed | In CISA | 14 Apr 2022 |
|
CVE-2022-22960
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in... |
VMware Workspace ONE Access, Identity Manager and vRealize Automation | Confirmed | In CISA | 15 Apr 2022 |
|
CVE-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator... |
Spring Cloud Gateway | Confirmed | In CISA | 16 May 2022 |
|
CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to... |
Spring Cloud Function | Confirmed | In CISA | 25 Aug 2022 |
|
CVE-2023-20887
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for... |
Aria Operations for Networks (Formerly vRealize Network Insight) | Confirmed | In CISA | 22 Jun 2023 |
|
CVE-2023-20867
VMware Tools Authentication Bypass Vulnerability |
VMware Tools | Confirmed | In CISA | 23 Jun 2023 |
|
CVE-2023-29552
The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the... |
Service Location Protocol (SLP) | Confirmed | In CISA | 08 Nov 2023 |
|
CVE-2023-34048
VMware vCenter Server Out-of-Bounds Write Vulnerability |
VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server) | Confirmed | In CISA | 22 Jan 2024 |
|
CVE-2022-22948
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative... |
VMware vCenter Server and VMware Cloud Foundation | Confirmed | In CISA | 17 Jul 2024 |
|
CVE-2024-37085
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full... |
VMware ESXi, VMware Cloud Foundation | Confirmed | In CISA | 30 Jul 2024 |
|
CVE-2024-38812
Heap-overflow vulnerability |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 20 Nov 2024 |
|
CVE-2024-38813
Privilege escalation vulnerability |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 20 Nov 2024 |
|
CVE-2025-22224
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious... |
ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure | Confirmed | In CISA | 04 Mar 2025 |
|
CVE-2025-22225
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel... |
VMware ESXi, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | Confirmed | In CISA | 04 Mar 2025 |
|
CVE-2025-22226
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious... |
ESXi, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | Confirmed | In CISA | 04 Mar 2025 |
No VMware CVEs match this search or filter.
Showing 39 of 39 VMware known exploited vulnerabilities.
Recurring weakness patterns
Control, server-side request forgery (ssrf), and out-of-bounds write account for twelve mapped occurrences across this VMware KEV portfolio.
CWE-94
Improper Control of Generation of Code ('Code Injection')
CWE-918
Server-Side Request Forgery (SSRF)
CWE-787
Out-of-bounds Write
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CWE-20
Improper Input Validation
CWE-287
Improper Authentication
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.