Vendor Exploitation Record

VMware — Known Exploited Vulnerabilities

29 in CISA KEV · 10 ransomware-linked · as of 2026-08-31
In CISA KEV29 confirmed exploited
Ransomware-linked10 (34% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2025-03-04

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to VMware (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited VMware vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2025-22226ESXi, Workstation, and FusionVMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability2025-03-04
CVE-2025-22225ESXiVMware ESXi Arbitrary Write Vulnerability2025-03-04ransomware
CVE-2025-22224ESXi and WorkstationVMware ESXi and Workstation TOCTOU Race Condition Vulnerability2025-03-04
CVE-2024-38813vCenter ServerVMware vCenter Server Privilege Escalation Vulnerability2024-11-20
CVE-2024-38812vCenter ServerVMware vCenter Server Heap-Based Buffer Overflow Vulnerability2024-11-20
CVE-2024-37085ESXiVMware ESXi Authentication Bypass Vulnerability2024-07-30ransomware
CVE-2022-22948vCenter ServerVMware vCenter Server Incorrect Default File Permissions Vulnerability 2024-07-17
CVE-2023-34048vCenter ServerVMware vCenter Server Out-of-Bounds Write Vulnerability2024-01-22
CVE-2023-20867ToolsVMware Tools Authentication Bypass Vulnerability2023-06-23
CVE-2023-20887Aria Operations for NetworksVmware Aria Operations for Networks Command Injection Vulnerability2023-06-22
CVE-2022-22963Spring CloudVMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability2022-08-25
CVE-2022-22947Spring Cloud GatewayVMware Spring Cloud Gateway Code Injection Vulnerability2022-05-16
CVE-2022-22960Multiple ProductsVMware Multiple Products Privilege Escalation Vulnerability2022-04-15
CVE-2022-22954Workspace ONE Access and Identity ManagerVMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability2022-04-14ransomware
CVE-2022-22965Spring FrameworkSpring Framework JDK 9+ Remote Code Execution Vulnerability2022-04-04
CVE-2020-5410Spring Cloud Configuration (Config) ServerVMware Tanzu Spring Cloud Config Directory Traversal Vulnerability2022-03-25
CVE-2018-6961SD-WAN EdgeVMware SD-WAN Edge by VeloCloud Command Injection Vulnerability2022-03-25
CVE-2018-1273Spring Data CommonsVMware Tanzu Spring Data Commons Property Binder Vulnerability2022-03-25ransomware
CVE-2021-21973vCenter Server and Cloud FoundationVMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability2022-03-07
CVE-2021-21975vRealize Operations Manager APIVMware Server Side Request Forgery in vRealize Operations Manager API2022-01-18ransomware
CVE-2021-22017vCenter ServerVMware vCenter Server Improper Access Control2022-01-10
CVE-2019-5544VMware ESXi and Horizon DaaSVMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability2021-11-03ransomware
CVE-2020-3992ESXiVMware ESXi OpenSLP Use-After-Free Vulnerability2021-11-03ransomware
CVE-2020-3950Multiple ProductsVMware Multiple Products Privilege Escalation Vulnerability2021-11-03
CVE-2021-22005vCenter ServerVMware vCenter Server File Upload Vulnerability2021-11-03ransomware
CVE-2020-3952vCenter ServerVMware vCenter Server Information Disclosure Vulnerability2021-11-03
CVE-2021-21972vCenter ServerVMware vCenter Server Remote Code Execution Vulnerability2021-11-03ransomware
CVE-2021-21985vCenter ServerVMware vCenter Server Improper Input Validation Vulnerability2021-11-03ransomware
CVE-2020-4006Multiple ProductsMultiple VMware Products Command Injection Vulnerability2021-11-03

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.