VMware Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for VMware products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

37

In CISA KEV

33

Beyond CISA KEV

4

Sensor Observed

0

Virtual Patch Available

0

VMware KEVs Added by Year

Loading...

37 VMware KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-22956

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A...

High Not in CISA 05 Feb 2026
CVE-2021-22053

Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within...

High Not in CISA 21 Aug 2025
CVE-2022-31656

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users....

High Not in CISA 31 Jul 2025
CVE-2021-22054

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37...

Confirmed In CISA 01 Jun 2026
CVE-2026-22719

VMware Aria Operations command injection vulnerability

Confirmed In CISA 01 Jun 2026
CVE-2024-37079

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to...

Confirmed In CISA 01 Jun 2026
CVE-2025-41244

VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)

Confirmed In CISA 01 Jun 2026
CVE-2021-21978

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of...

High Not in CISA 22 Apr 2025
CVE-2020-4006

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Confirmed In CISA 03 Nov 2021
CVE-2021-21985

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in...

Confirmed In CISA 03 Nov 2021
CVE-2021-21972

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port...

Confirmed In CISA 03 Nov 2021
CVE-2020-3952

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does...

Confirmed In CISA 03 Nov 2021
CVE-2021-22005

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on...

Confirmed In CISA 03 Nov 2021
CVE-2020-3950

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before...

Confirmed In CISA 03 Nov 2021
CVE-2020-3992

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a...

Confirmed In CISA 03 Nov 2021
CVE-2019-5544

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the...

Confirmed In CISA 03 Nov 2021
CVE-2021-22017

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network...

Confirmed In CISA 10 Jan 2022
CVE-2021-21975

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...

Confirmed In CISA 18 Jan 2022
CVE-2021-21973

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server...

Confirmed In CISA 07 Mar 2022
CVE-2018-6961

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component...

Confirmed In CISA 25 Mar 2022
CVE-2020-5410

Directory Traversal with spring-cloud-config-server

Confirmed In CISA 25 Mar 2022
CVE-2022-22965

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...

Confirmed In CISA 04 Apr 2022
CVE-2022-22954

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious...

Confirmed In CISA 14 Apr 2022
CVE-2022-22960

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in...

Confirmed In CISA 15 Apr 2022
CVE-2022-22947

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator...

Confirmed In CISA 16 May 2022

Common Vulnerability Classes (CWE)

  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 5
  • CWE-918 — Server-Side Request Forgery (SSRF) 4
  • CWE-787 — Out-of-bounds Write 3
  • CWE-917 — Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') 2
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
  • CWE-20 — Improper Input Validation 2
  • CWE-287 — Improper Authentication 2

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology