VMware Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for VMware products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
37
In CISA KEV
33
Beyond CISA KEV
4
Sensor Observed
0
Virtual Patch Available
0
VMware KEVs Added by Year
37 VMware KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-22956
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A... |
Workspace ONE Access | High | Not in CISA | 05 Feb 2026 |
|
CVE-2021-22053
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within... |
Spring Cloud Netflix Hystrix Dashboard | High | Not in CISA | 21 Aug 2025 |
|
CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.... |
Workspace ONE Access, Identity Manager, vRealize Automation | High | Not in CISA | 31 Jul 2025 |
|
CVE-2021-22054
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37... |
Workspace ONE UEM | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-22719
VMware Aria Operations command injection vulnerability |
VMware Aria Operations, VMware Cloud Foundation Operations, Telco Cloud Platform, Telco Cloud Infrastructure | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2024-37079
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to... |
vCenter Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-41244
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) |
VCF operations, VMware tools, VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-21978
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of... |
VMware View Planner | High | Not in CISA | 22 Apr 2025 |
|
CVE-2020-4006
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
VMware Workspace One Access (Access), VMware Workspace One Access Connector (Access Connector), VMware Identity Manager (vIDM), VMware Identity Manager Connector (vIDM Connector), VMware Cloud Foundation, vRealize Suite Lifecycle Manager | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-21985
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in... |
VMware vCenter Server and VMware Cloud Foundation | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-21972
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3952
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does... |
VMware vCenter Server | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22005
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3950
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before... |
VMware Fusion, VMware Remote Console for Mac and Horizon Client for Mac | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-3992
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a... |
VMware ESXi | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-5544
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the... |
ESXi and Horizon DaaS | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22017
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 10 Jan 2022 |
|
CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the... |
VMware vRealize Operations | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2021-21973
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server... |
VMware vCenter Server, VMware Cloud Foundation | Confirmed | In CISA | 07 Mar 2022 |
|
CVE-2018-6961
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component... |
NSX SD-WAN by VeloCloud | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2020-5410
Directory Traversal with spring-cloud-config-server |
Spring Cloud Config | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific... |
Spring Framework | Confirmed | In CISA | 04 Apr 2022 |
|
CVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious... |
VMware Workspace ONE Access and Identity Manager | Confirmed | In CISA | 14 Apr 2022 |
|
CVE-2022-22960
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in... |
VMware Workspace ONE Access, Identity Manager and vRealize Automation | Confirmed | In CISA | 15 Apr 2022 |
|
CVE-2022-22947
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator... |
Spring Cloud Gateway | Confirmed | In CISA | 16 May 2022 |
Common Vulnerability Classes (CWE)
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
- CWE-918 — Server-Side Request Forgery (SSRF) 4
- CWE-787 — Out-of-bounds Write 3
- CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 2
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-20 — Improper Input Validation 2
- CWE-287 — Improper Authentication 2
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology