VMware Vulnerabilities and Affected Products
Vulnerabilities associated with Telco Cloud Infrastructure.
Products
Clear product- Workstation54 vulnerabilities
- Fusion49 vulnerabilities
- ESXi33 vulnerabilities
- Cloud Foundation17 vulnerabilities
- cloud_foundation17 vulnerabilities
- Telco Cloud Platform17 vulnerabilities
- vCenter Server15 vulnerabilities
- VMware Aria Operations15 vulnerabilities
- Telco Cloud Infrastructure14 vulnerabilities
- VMware ESXi14 vulnerabilities
- Spring Framework12 vulnerabilities
- SALT11 vulnerabilities
- Horizon View Client for Windows9 vulnerabilities
- Avi Load Balancer8 vulnerabilities
- VMware Telco Cloud Platform8 vulnerabilities
- vSphere Foundation7 vulnerabilities
- Workstation Pro / Player6 vulnerabilities
- Workstation Pro/Player6 vulnerabilities
- Fusion Pro / Fusion5 vulnerabilities
- nsx5 vulnerabilities
- Spring AI5 vulnerabilities
- VMware Cloud Foundation5 vulnerabilities
- VMware Cloud Foundation (vCenter Server)5 vulnerabilities
- VMware Fusion5 vulnerabilities
- VMware vCenter Server (vCenter Server)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-59309CRITICAL | vCenter authentication-bypass vulnerabilityVMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. CWE-303Jul 30, 2026 | CVSS9.8v3.1 | EPSS0.744% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59310CRITICAL | Generated title:VMware vCenter Syslog Server Directory Traversal Remote Code ExecutionVMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. CWE-22Jul 30, 2026 | CVSS9.8v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22719HIGH | VMware Aria Operations command injection vulnerabilityVMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 … CWE-77Feb 25, 2026 | CVSS8.1v3.1 | EPSS17.4% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41250HIGH | Header injection vulnerabilityVMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks. CWE-77Sep 29, 2025 | CVSS8.5v3.1 | EPSS0.638% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41241MEDIUM | Denial-of-service vulnerabilityVMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition. CWE-754Jul 29, 2025 | CVSS4.4v3.1 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41239HIGH | vSockets information-disclosure vulnerabilityVMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of an uninitialised memory in vSockets. A malicious actor with local administrative privileges on a virtual machine may be able to exploit this issue to leak memory from processes communicating with vSockets. CWE-908Jul 15, 2025 | CVSS7.1v3.1 | EPSS2.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41238CRITICAL | PVSCSI heap-overflow vulnerabilityVMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox and exploitable only with configurations that are unsupported. On Workstation and Fusion, this may lead … CWE-787Jul 15, 2025 | CVSS9.3v3.1 | EPSS0.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41237CRITICAL | VMCI integer-underflow vulnerabilityVMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion … CWE-787Jul 15, 2025 | CVSS9.3v3.1 | EPSS0.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41236CRITICAL | VMXNET3 integer-overflow vulnerabilityVMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. CWE-787Jul 15, 2025 | CVSS9.3v3.1 | EPSS2.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41228MEDIUM | VMware ESXi and vCenter Server Reflected Cross Site Scripting (XSS) VulnerabilityVMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites. CWE-79May 20, 2025 | CVSS4.3v3.1 | EPSS0.857% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41227MEDIUM | Denial-of-Service VulnerabilityVMware ESXi, Workstation, and Fusion contain a denial-of-service vulnerability due to certain guest options. A malicious actor with non-administrative privileges within a guest operating system may be able to exploit this issue by exhausting memory of the host process leading to a denial-of-service condition. CWE-400May 20, 2025 | CVSS5.5v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41226MEDIUM | Guest Operations Denial-of-Service VulnerabilityVMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled. CWE-400May 20, 2025 | CVSS6.8v3.1 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-41225HIGH | VMware vCenter Server authenticated command-execution vulnerabilityThe vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server. CWE-78May 20, 2025 | CVSS8.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-22224CRITICAL | VMware ESXi and Workstation TOCTOU Race Condition VulnerabilityVMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. CWE-367Mar 4, 2025 | CVSS9.3v3.1 | EPSS1.56% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |