EXPOSURES › CVE-2021-21972
CVE-2021-21972
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
ransomwarerceexploited-in-wildunpatched
VMware vCenter Server RCE due to unpatched plugin exploited in wild
VMware vCenter Server vSphere Client plugin allowed remote attackers to execute unrestricted commands via port 443, leading to RCE.
Shame score — Critical RCE in widely used product exploited before patching
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.60
VMware's critical RCE flaw in vCenter Server was widely condemned by security press and authorities, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout a
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation."
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"A China-linked threat actor has spent seven months exploiting a maximum-severity authentication bypass in Oracle's enterprise web middleware — across government and commercial networks in more than 100 countries — and on August 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency confirmed the ongoing exploitation and imposed its tightest possible emergency patch mandate, ordering e"
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"CVEs in KEV"
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"CISA Adds One Known Exploited Vulnerability to Catalog"
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
Severe condemnation of VMware's critical RCE flaw in vCenter Server, with no praise for the vendor's handling.
"VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system."
AFFECTED FEDRAMP PRODUCTS · 2
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |