Vendor

VMware

As of , 26 VMware vulnerabilities are on CISA's list of exploited vulnerabilities, 9 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2020-3950.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2020-3950Privilege EscalationVMware Multiple ProductsPatch this weekMetasploit module; verified Exploit-DB entry0.07
2CVE-2023-20887Command InjectionVMware Aria Operations for NetworksPatch this weekMetasploit module; EPSS 0.980.98
3CVE-2022-22947Code InjectionVMware Spring Cloud GatewayPatch this weekMetasploit module; EPSS 0.980.98
4CVE-2022-22954Server-Side Template InjectionVMware Workspace ONE Access and Identity ManagerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
5CVE-2022-22965JDK 9+ Remote Code ExecutionVMware Spring FrameworkPatch this weekMetasploit module; EPSS 0.990.99
6CVE-2021-21975Server Side Request Forgery in vRealize Operations Manager APIVMware vRealize Operations Manager APIPatch this weekRansomware use; Metasploit module; EPSS 0.780.78
7CVE-2020-3952Information DisclosureVMware vCenter ServerPatch this weekMetasploit module; EPSS 0.900.90
8CVE-2021-21972Remote Code ExecutionVMware vCenter ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
9CVE-2021-21985Improper Input ValidationVMware vCenter ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
10CVE-2021-22005File UploadVMware vCenter ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
11CVE-2022-22960Privilege EscalationVMware Multiple ProductsPatch this weekMetasploit module0.36
12CVE-2022-22948Incorrect Default File PermissionsVMware vCenter ServerPatch this weekMetasploit module0.13
13CVE-2018-6961by VeloCloud Command InjectionVMware SD-WAN EdgePatch this weekEPSS 0.86; verified Exploit-DB entry0.86
14CVE-2023-34048Out-of-Bounds WriteVMware vCenter ServerPatch this weekEPSS 0.990.99
15CVE-2021-21973Server Side Request Forgery (SSRF)VMware vCenter Server and Cloud FoundationPatch this weekEPSS 0.880.88
16CVE-2019-5544OpenSLP Heap-Based Buffer OverflowVMware VMware ESXi and Horizon DaaSPatch this weekRansomware use; EPSS 0.970.97
17CVE-2020-3992OpenSLP Use-After-FreeVMware ESXiPatch this weekRansomware use; EPSS 0.830.83
18CVE-2024-38812Heap-Based Buffer OverflowVMware vCenter ServerPatch this weekEPSS 0.550.55
19CVE-2024-37085Authentication BypassVMware ESXiPatch this weekRansomware use0.27
20CVE-2025-22225Arbitrary WriteVMware ESXiPatch this weekRansomware use0.01
21CVE-2021-22017Improper Access ControlVMware vCenter ServerPatch soon0.49
22CVE-2024-38813Privilege EscalationVMware vCenter ServerPatch soon0.17
23CVE-2020-4006Multiple VMware Products Command InjectionVMware Multiple ProductsPatch soon0.17
24CVE-2023-20867Authentication BypassVMware ToolsPatch soon0.14
25CVE-2025-22226Information DisclosureVMware ESXi, Workstation, and FusionPatch soon0.02

The next 1, from number 26

Products

  • vCenter Server9 entries
  • ESXi3 entries
  • Multiple Products3 entries
  • Aria Operations for Networks1 entry
  • ESXi and Workstation1 entry
  • ESXi, Workstation, and Fusion1 entry
  • SD-WAN Edge1 entry
  • Spring Cloud Gateway1 entry
  • Spring Framework1 entry
  • Tools1 entry
  • vCenter Server and Cloud Foundation1 entry
  • VMware ESXi and Horizon DaaS1 entry
  • vRealize Operations Manager API1 entry
  • Workspace ONE Access and Identity Manager1 entry

Added each year

24682021: 8820212022: 8820222023: 2220232024: 5520242025: 3320252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20218
20228
20232
20245
20253
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-22225 VMware ESXiRansomware use: Unknown to Known.
  2. CVE-2025-22225 VMware ESXiEdited: weakness list.

Every change we recorded