VMware known exploited vulnerabilities
CISA lists 26 VMware CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-03-04), and 9 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-22005 (vCenter Server): EPSS 100.0%, added 2021-11-03
- CVE-2021-21985 (vCenter Server): EPSS 100.0%, added 2021-11-03
- CVE-2022-22954 (Workspace ONE Access and Identity Manager): EPSS 100.0%, added 2022-04-14
- CVE-2021-21972 (vCenter Server): EPSS 99.9%, added 2021-11-03
- CVE-2022-22965 (Spring Framework): EPSS 99.6%, added 2022-04-04
Most affected VMware products
vCenter Server (9), ESXi (3), Multiple Products (3), ESXi, Workstation, and Fusion (1), ESXi and Workstation (1), Tools (1), Aria Operations for Networks (1), Spring Cloud Gateway (1), Workspace ONE Access and Identity Manager (1), Spring Framework (1), SD-WAN Edge (1), vCenter Server and Cloud Foundation (1).
All VMware CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2025-22226 | ESXi, Workstation, and Fusion | ESXi, Workstation, and Fusion Information Disclosure | 2025-03-04 | 2025-03-25 | 1.8% | – |
| CVE-2025-22225 | ESXi | ESXi Arbitrary Write | 2025-03-04 | 2025-03-25 | 1.0% | Yes |
| CVE-2025-22224 | ESXi and Workstation | ESXi and Workstation TOCTOU Race Condition | 2025-03-04 | 2025-03-25 | 1.6% | – |
| CVE-2024-38813 | vCenter Server | vCenter Server Privilege Escalation | 2024-11-20 | 2024-12-11 | 17.4% | – |
| CVE-2024-38812 | vCenter Server | vCenter Server Heap-Based Buffer Overflow | 2024-11-20 | 2024-12-11 | 54.6% | – |
| CVE-2024-37085 | ESXi | ESXi Authentication Bypass | 2024-07-30 | 2024-08-20 | 26.8% | Yes |
| CVE-2022-22948 | vCenter Server | vCenter Server Incorrect Default File Permissions | 2024-07-17 | 2024-08-07 | 13.3% | – |
| CVE-2023-34048 | vCenter Server | vCenter Server Out-of-Bounds Write | 2024-01-22 | 2024-02-12 | 99.4% | – |
| CVE-2023-20867 | Tools | Tools Authentication Bypass | 2023-06-23 | 2023-07-14 | 13.5% | – |
| CVE-2023-20887 | Aria Operations for Networks | Vmware Aria Operations for Networks Command Injection | 2023-06-22 | 2023-07-13 | 98.3% | – |
| CVE-2022-22947 | Spring Cloud Gateway | Spring Cloud Gateway Code Injection | 2022-05-16 | 2022-06-06 | 98.3% | – |
| CVE-2022-22960 | Multiple Products | Multiple Products Privilege Escalation | 2022-04-15 | 2022-05-06 | 35.5% | – |
| CVE-2022-22954 | Workspace ONE Access and Identity Manager | Workspace ONE Access and Identity Manager Server-Side Template Injection | 2022-04-14 | 2022-05-05 | 100.0% | Yes |
| CVE-2022-22965 | Spring Framework | Spring Framework JDK 9+ Remote Code Execution | 2022-04-04 | 2022-04-25 | 99.6% | – |
| CVE-2018-6961 | SD-WAN Edge | SD-WAN Edge by VeloCloud Command Injection | 2022-03-25 | 2022-04-15 | 86.3% | – |
| CVE-2021-21973 | vCenter Server and Cloud Foundation | vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) | 2022-03-07 | 2022-03-21 | 87.6% | – |
| CVE-2021-21975 | vRealize Operations Manager API | Server Side Request Forgery in vRealize Operations Manager API | 2022-01-18 | 2022-02-01 | 78.3% | Yes |
| CVE-2021-22017 | vCenter Server | vCenter Server Improper Access Control | 2022-01-10 | 2022-01-24 | 49.2% | – |
| CVE-2021-22005 | vCenter Server | vCenter Server File Upload | 2021-11-03 | 2021-11-17 | 100.0% | Yes |
| CVE-2021-21985 | vCenter Server | vCenter Server Improper Input Validation | 2021-11-03 | 2021-11-17 | 100.0% | Yes |
| CVE-2021-21972 | vCenter Server | vCenter Server Remote Code Execution | 2021-11-03 | 2021-11-17 | 99.9% | Yes |
| CVE-2020-4006 | Multiple Products | Multiple Products Command Injection | 2021-11-03 | 2022-05-03 | 17.3% | – |
| CVE-2020-3992 | ESXi | ESXi OpenSLP Use-After-Free | 2021-11-03 | 2022-05-03 | 83.0% | Yes |
| CVE-2020-3952 | vCenter Server | vCenter Server Information Disclosure | 2021-11-03 | 2022-05-03 | 90.4% | – |
| CVE-2020-3950 | Multiple Products | Multiple Products Privilege Escalation | 2021-11-03 | 2022-05-03 | 7.3% | – |
| CVE-2019-5544 | VMware ESXi and Horizon DaaS | ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow | 2021-11-03 | 2022-05-03 | 97.3% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors