Product of VMware

ESXi

As of , 3 VMware ESXi vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2020-3992.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2020-3992OpenSLP Use-After-FreeVMware ESXiPatch this weekRansomware use; EPSS 0.830.83
2CVE-2024-37085Authentication BypassVMware ESXiPatch this weekRansomware use0.27
3CVE-2025-22225Arbitrary WriteVMware ESXiPatch this weekRansomware use0.01

Added each year

0.512021: 1120212022: nonenone20222023: nonenone20232024: 1120242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
2022none
2023none
20241
20251
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-22225 VMware ESXiRansomware use: Unknown to Known.
  2. CVE-2025-22225 VMware ESXiEdited: weakness list.

Every change we recorded