← Back to Vulnerability Reports CVE Intelligence

CVE-2026-21985

VMware ESXi 7.x / 8.xMEDIUM · CVSS 6No exploitation reported
CVSS6 NVD 3.1
SeverityMEDIUM
ExploitationNo exploitation reported
Triage statusNo Known Exploit
ActionSchedule for next cycle
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Affected product

VMware ESXi 7.x / 8.x

Remediation Steps

  1. Apply VMware patch VMSA-2026-0004 to all ESXi hosts.
  2. If patching is not possible within 24 hours, disable OpenSLP service as temporary mitigation.
  3. Scan ESXi host logs for indicators of compromise: unusual VM creation or encrypted VMDK files.
  4. Verify backup integrity for all virtual machines on affected hosts.
  5. Monitor network traffic from ESXi management interfaces for outbound connections to unknown IPs.
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.