Skip to content
COOEY

FAIL › dossier

Virtual System/Server Administrator (VSA)

PRODUCT

· dossier confidence 50%

VisionSys AI (VSA) has a history of critical vulnerabilities in its VSA product, leading to ransomware attacks and delayed remediation. The company's security posture requires significant improvement to meet CMMC requirements and mitigate exploitation risks.

PROFILE
CategoryCybersecurityWhat they doVisionSys AI Inc. (VSA) provides cloud-based cybersecurity solutions, including a virtual system administrator (VSA) product. The company is publicly traded on the NASDAQ.Size621.51K shares outstanding Websitehttps://stockanalysis.com/stocks/vsa/ ↗
SECURITY POSTURE

Kaseya VSA has a history of critical vulnerabilities leading to ransomware attacks, indicating significant security weaknesses in the product's design and implementation.

Notable failures
  • CVE-2017-18362 (SQL injection, RCE)
  • CVE-2018-20753 (PowerShell RCE)
  • CVE-2021-30116 (Session ID exposure)
Patterns: Critical Remote Code Execution (RCE) vulnerabilities; Vulnerabilities leading to ransomware infections; Delayed remediation of known vulnerabilities (median 43 days in 2025)
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-05-24 CVE-2017-18362 critical A Kaseya VSA SQL injection vulnerability allowed unauthenticated remote access to the database, linked to ransomware attacks.
2022-04-13 CVE-2018-20753 critical The Kaseya VSA vulnerability allowed attackers to remotely execute PowerShell on managed devices, leading to ransomware infections across numerous organizations.
2021-11-03 CVE-2021-30116 critical Kaseya VSA exposed session IDs, enabling attackers to compromise systems and potentially deploy ransomware.
Open questions: What specific remediation steps have been taken to address the root causes of these vulnerabilities? · What is the current status of third-party audits and penetration testing of the VSA? · What is the extent of the impact on MSPs and their clients?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:00:25.404788+00:00