VMware vendor intelligence

VMware Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting VMware products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse VMware KEVs Full KEV feed
Total KEVs
39
Known exploited vulnerabilities affecting VMware products
In CISA KEV
34
Records also listed in the official catalog
Beyond CISA KEV
5
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
VMware KEVs with sensor-observed exploitation activity

The catalog gap matters for VMware exposure

Five of the 39 exploited VMware CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 13% of this vendor portfolio.

87%
Covered by CISA
13%
Beyond CISA
32
Product families

Attested VMware CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-59310

vCenter directory-traversal vulnerability

Cloud Foundation, vSphere Foundation, vCenter, Telco Cloud Infrastructure, Telco Cloud Platform Confirmed In CISA 12 Aug 2026
CVE-2021-21983

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with...

VMware vRealize Operations High Beyond CISA 12 Aug 2026
CVE-2022-22956

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A...

Workspace ONE Access High Beyond CISA 05 Feb 2026
CVE-2021-22053

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within...

Spring Cloud Netflix Hystrix Dashboard High Beyond CISA 21 Aug 2025
CVE-2022-31656

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users....

Workspace ONE Access, Identity Manager, vRealize Automation High Beyond CISA 31 Jul 2025
CVE-2021-22054

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37...

Workspace ONE UEM Confirmed In CISA 01 Jun 2026
CVE-2026-22719

VMware Aria Operations command injection vulnerability

VMware Aria Operations, VMware Cloud Foundation Operations, Telco Cloud Platform, Telco Cloud Infrastructure Confirmed In CISA 01 Jun 2026
CVE-2024-37079

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to...

vCenter Server Confirmed In CISA 01 Jun 2026
CVE-2025-41244

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

VCF operations, VMware tools, VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure Confirmed In CISA 01 Jun 2026
CVE-2021-21978

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of...

VMware View Planner High Beyond CISA 22 Apr 2025
CVE-2020-4006

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware Identity Manager (vIDM), VMware Identity Manager Connector (vIDM Connector), VMware Cloud Foundation, vRealize Suite Lifecycle Manager Confirmed In CISA 03 Nov 2021
CVE-2021-21985

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in...

VMware vCenter Server and VMware Cloud Foundation Confirmed In CISA 03 Nov 2021
CVE-2021-21972

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port...

VMware vCenter Server, VMware Cloud Foundation Confirmed In CISA 03 Nov 2021
CVE-2020-3952

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does...

VMware vCenter Server Confirmed In CISA 03 Nov 2021
CVE-2021-22005

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on...

VMware vCenter Server, VMware Cloud Foundation Confirmed In CISA 03 Nov 2021
CVE-2020-3950

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before...

VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac Confirmed In CISA 03 Nov 2021
CVE-2020-3992

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a...

VMware ESXi Confirmed In CISA 03 Nov 2021
CVE-2019-5544

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the...

ESXi and Horizon DaaS Confirmed In CISA 03 Nov 2021
CVE-2021-22017

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network...

VMware vCenter Server, VMware Cloud Foundation Confirmed In CISA 10 Jan 2022
CVE-2021-21975

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...

VMware vRealize Operations Confirmed In CISA 18 Jan 2022
CVE-2021-21973

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server...

VMware vCenter Server, VMware Cloud Foundation Confirmed In CISA 07 Mar 2022
CVE-2018-6961

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component...

NSX SD-WAN by VeloCloud Confirmed In CISA 25 Mar 2022
CVE-2020-5410

Directory Traversal with spring-cloud-config-server

Spring Cloud Config Confirmed In CISA 25 Mar 2022
CVE-2022-22965

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...

Spring Framework Confirmed In CISA 04 Apr 2022
CVE-2022-22954

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious...

VMware Workspace ONE Access and Identity Manager Confirmed In CISA 14 Apr 2022
CVE-2022-22960

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in...

VMware Workspace ONE Access, Identity Manager and vRealize Automation Confirmed In CISA 15 Apr 2022
CVE-2022-22947

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator...

Spring Cloud Gateway Confirmed In CISA 16 May 2022
CVE-2022-22963

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to...

Spring Cloud Function Confirmed In CISA 25 Aug 2022
CVE-2023-20887

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for...

Aria Operations for Networks (Formerly vRealize Network Insight) Confirmed In CISA 22 Jun 2023
CVE-2023-20867

VMware Tools Authentication Bypass Vulnerability

VMware Tools Confirmed In CISA 23 Jun 2023
CVE-2023-29552

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the...

Service Location Protocol (SLP) Confirmed In CISA 08 Nov 2023
CVE-2023-34048

VMware vCenter Server Out-of-Bounds Write Vulnerability

VMware vCenter Server, VMware Cloud Foundation (VMware vCenter Server) Confirmed In CISA 22 Jan 2024
CVE-2022-22948

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative...

VMware vCenter Server and VMware Cloud Foundation Confirmed In CISA 17 Jul 2024
CVE-2024-37085

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full...

VMware ESXi, VMware Cloud Foundation Confirmed In CISA 30 Jul 2024
CVE-2024-38812

Heap-overflow vulnerability

VMware vCenter Server, VMware Cloud Foundation Confirmed In CISA 20 Nov 2024
CVE-2024-38813

Privilege escalation vulnerability

VMware vCenter Server, VMware Cloud Foundation Confirmed In CISA 20 Nov 2024
CVE-2025-22224

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious...

ESXi, Workstation, VMware Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure Confirmed In CISA 04 Mar 2025
CVE-2025-22225

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel...

VMware ESXi, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure Confirmed In CISA 04 Mar 2025
CVE-2025-22226

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious...

ESXi, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure Confirmed In CISA 04 Mar 2025

Showing 39 of 39 VMware known exploited vulnerabilities.

Recurring weakness patterns

Control, server-side request forgery (ssrf), and out-of-bounds write account for twelve mapped occurrences across this VMware KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.