CyberMax
Home › Exploited CVEs

VMware known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 26 VMware CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-03-04), and 9 are known to be used in ransomware campaigns.

VMware CVEs added to CISA KEV per year
2021: 8202182022: 8202282023: 2202322024: 5202452025: 320253

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected VMware products

vCenter Server (9), ESXi (3), Multiple Products (3), ESXi, Workstation, and Fusion (1), ESXi and Workstation (1), Tools (1), Aria Operations for Networks (1), Spring Cloud Gateway (1), Workspace ONE Access and Identity Manager (1), Spring Framework (1), SD-WAN Edge (1), vCenter Server and Cloud Foundation (1).

All VMware CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2025-22226ESXi, Workstation, and FusionESXi, Workstation, and Fusion Information Disclosure2025-03-042025-03-251.8%–
CVE-2025-22225ESXiESXi Arbitrary Write2025-03-042025-03-251.0%Yes
CVE-2025-22224ESXi and WorkstationESXi and Workstation TOCTOU Race Condition2025-03-042025-03-251.6%–
CVE-2024-38813vCenter ServervCenter Server Privilege Escalation2024-11-202024-12-1117.4%–
CVE-2024-38812vCenter ServervCenter Server Heap-Based Buffer Overflow2024-11-202024-12-1154.6%–
CVE-2024-37085ESXiESXi Authentication Bypass2024-07-302024-08-2026.8%Yes
CVE-2022-22948vCenter ServervCenter Server Incorrect Default File Permissions2024-07-172024-08-0713.3%–
CVE-2023-34048vCenter ServervCenter Server Out-of-Bounds Write2024-01-222024-02-1299.4%–
CVE-2023-20867ToolsTools Authentication Bypass2023-06-232023-07-1413.5%–
CVE-2023-20887Aria Operations for NetworksVmware Aria Operations for Networks Command Injection2023-06-222023-07-1398.3%–
CVE-2022-22947Spring Cloud GatewaySpring Cloud Gateway Code Injection2022-05-162022-06-0698.3%–
CVE-2022-22960Multiple ProductsMultiple Products Privilege Escalation2022-04-152022-05-0635.5%–
CVE-2022-22954Workspace ONE Access and Identity ManagerWorkspace ONE Access and Identity Manager Server-Side Template Injection2022-04-142022-05-05100.0%Yes
CVE-2022-22965Spring FrameworkSpring Framework JDK 9+ Remote Code Execution2022-04-042022-04-2599.6%–
CVE-2018-6961SD-WAN EdgeSD-WAN Edge by VeloCloud Command Injection2022-03-252022-04-1586.3%–
CVE-2021-21973vCenter Server and Cloud FoundationvCenter Server and Cloud Foundation Server Side Request Forgery (SSRF)2022-03-072022-03-2187.6%–
CVE-2021-21975vRealize Operations Manager APIServer Side Request Forgery in vRealize Operations Manager API2022-01-182022-02-0178.3%Yes
CVE-2021-22017vCenter ServervCenter Server Improper Access Control2022-01-102022-01-2449.2%–
CVE-2021-22005vCenter ServervCenter Server File Upload2021-11-032021-11-17100.0%Yes
CVE-2021-21985vCenter ServervCenter Server Improper Input Validation2021-11-032021-11-17100.0%Yes
CVE-2021-21972vCenter ServervCenter Server Remote Code Execution2021-11-032021-11-1799.9%Yes
CVE-2020-4006Multiple ProductsMultiple Products Command Injection2021-11-032022-05-0317.3%–
CVE-2020-3992ESXiESXi OpenSLP Use-After-Free2021-11-032022-05-0383.0%Yes
CVE-2020-3952vCenter ServervCenter Server Information Disclosure2021-11-032022-05-0390.4%–
CVE-2020-3950Multiple ProductsMultiple Products Privilege Escalation2021-11-032022-05-037.3%–
CVE-2019-5544VMware ESXi and Horizon DaaSESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow2021-11-032022-05-0397.3%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors