EXPOSURES › CVE-2020-3992
CVE-2020-3992
CRITICAL ⌖ ON CISA KEV · EXPLOITEDVMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.
CVE-2020-3992 in VMware ESXi allowed remote code execution via port 427, and was actively exploited, including by ransomware. DIB organizations using ESXi must immediately patch and segment management networks to prevent compromise; failure to do so violates NIST 800-171 controls related to access control and vulnerability management.
Shame score — A critical, remotely exploitable vulnerability with ransomware links demonstrates a significant failure in VMware's secure development lifecycle and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
"A single flaw in VMware vCenter has turned into one of the more consequential enterprise-security stories of August 2026."
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog."
"VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution."
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |