EXPOSURES › CVE-2021-22005
CVE-2021-22005
CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
⌖ EXPLOITED IN THE WILD
SHAME 80/100
ransomwareexploited-in-wild
VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.60
VMware faced severe fallout due to actively exploited zero-day vulnerabilities in ESXi, leading to ransomware attacks and urgent patch releases under Broadcom ownership.
The Hacker News reports on actively exploited VMware security flaws, with Broadcom releasing urgent patches.
"Broadcom has released security updates to address three actively exploited security flaws in VMware ESXi, Workstation, and Fusion products that could lead to code execution and information disclosure."
CISA warns of active exploitation of VMware ESXi zero-day vulnerabilities in ransomware attacks, highlighting severe fallout.
"CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability."
Huntress reports on active exploitation of ESXi vulnerabilities in the wild, indicating severe security failures.
"ESXi Exploitation in the Wild"
NVD confirms the severity of the file upload vulnerability in VMware vCenter Server, allowing code execution via port 443.
"VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code."
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
AFFECTED FEDRAMP PRODUCTS · 2
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |