Skip to content
COOEY

FAIL › dossier

VMware, Inc.

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

VMware is a major virtualization vendor with a severe security history dominated by critical RCE vulnerabilities in its core products like ESXi and vCenter. Many of these flaws are actively exploited by ransomware and other threat actors, and the company struggles with patching and default configurations that expose its infrastructure to network-accessible attacks.

PROFILE
CategoryvirtualizationWhat they doVMware provides enterprise virtualization, cloud management, and networking software including ESXi, vCenter, and Workspace ONE. Websitehttps://www.vmware.com ↗
SECURITY POSTURE

VMware has a poor security track record characterized by a high frequency of critical remote code execution (RCE) vulnerabilities across its core virtualization stack, including ESXi and vCenter, many of which are actively exploited on the CISA KEV list.

Notable failures
  • CVE-2025-22225: Critical arbitrary write in ESXi enabling sandbox escapes and active ransomware exploitation
  • CVE-2022-22954: Critical RCE in Workspace ONE Access via server-side template injection
  • CVE-2021-21985: Critical RCE in vSphere Client via improper input validation in Virtual SAN Health Check
Patterns: repeated critical RCEs in core virtualization components (ESXi, vCenter); active exploitation of vulnerabilities on the CISA KEV list; vulnerabilities in default or enabled services (e.g., Virtual SAN Health Check, OpenSLP)
FAILURE HISTORY · 34
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-21985 critical VMware vCenter Server RCE due to unpatched input validation flaw
2025-03-04 CVE-2025-22225 critical A critical arbitrary write vulnerability in VMware ESXi allows sandbox escapes and is actively exploited by ransomware.
2024-11-20 CVE-2024-38813 high VMware vCenter Server allows remote privilege escalation to root via a dropped privileges check bypass, enabling attackers to gain full control of the system.
2024-01-22 CVE-2023-34048 high VMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.
2021-11-03 CVE-2020-3952 high An unpatched directory traversal flaw in VMware vCenter's Syslog server allowed unauthenticated attackers to gain persistent remote access via reverse SSH backdoors.
2021-11-03 CVE-2021-22005 critical VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.
2024-07-30 CVE-2024-37085 critical VMware ESXi allows attackers with AD permissions to regain full host access by recreating a deleted admin group.
2022-04-04 CVE-2022-22965 high VMware Spring Framework apps on JDK 9+ suffered remote code execution via data binding.
2022-03-25 CVE-2018-6961 high VMware SD-WAN Edge suffered a command injection flaw in its local web UI allowing remote code execution.
2022-03-07 CVE-2021-21973 high Attackers exploited an unpatched SSRF vulnerability in VMware vCenter Server to gain persistent remote access and deploy backdoors.
2022-01-10 CVE-2021-22017 high Attackers exploited a directory-traversal flaw in VMware vCenter's Syslog server to gain persistent remote access.
2021-11-03 CVE-2020-3950 high Improper use of setuid binaries in VMware Fusion, VMRC, and Horizon Client for Mac allowed privilege escalation to root.
2021-11-03 CVE-2020-4006 high Command injection flaw in VMware Workspace One products allowed attackers with admin access to execute unrestricted OS commands.
2022-05-16 CVE-2022-22947 high VMware Spring Cloud Gateway allows code injection via its exposed and unsecured Actuator endpoint when enabled.
2025-03-04 CVE-2025-22226 high VMware virtualization products have an information disclosure vulnerability actively exploited in the wild, potentially allowing memory leakage from privileged virtual machines.
2023-06-23 CVE-2023-20867 high VMware Tools Authentication Bypass Vulnerability
2023-06-22 CVE-2023-20887 high VMware Aria Operations for Networks command injection vulnerability allows remote code execution.
2022-04-14 CVE-2022-22954 critical VMware Workspace ONE Access suffered a server-side template injection vulnerability enabling remote code execution and actively exploited by ransomware actors.
2022-01-18 CVE-2021-21975 critical VMware's vRealize Operations Manager API had a critical SSRF vulnerability exploited in the wild, potentially leading to credential theft and system compromise.
2021-11-03 CVE-2021-21972 critical VMware vCenter Server RCE due to unpatched plugin exploited in wild
2021-11-03 CVE-2019-5544 critical VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).
2021-11-03 CVE-2020-3992 critical VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.
2022-04-15 CVE-2022-22960 high VMware Workspace ONE Access, Identity Manager, and vRealize Automation suffered a privilege escalation vulnerability due to improper permissions in support scripts.
2025-03-04 CVE-2025-22224 high VMware ESXi and Workstation vulnerabilities allow code execution with local admin privileges, and are currently being exploited in the wild.
2024-11-20 CVE-2024-38812 high VMware vCenter Server exploited via heap-based buffer overflow enabling remote code execution.
2024-07-17 CVE-2022-22948 high VMware vCenter Server shipped with incorrect default file permissions enabling remote privileged attackers to access sensitive data.
2026-06-11 CVE-2026-41699 high CVE-2026-41699: Spring for GraphQL applications are vulnerable to Unsafe Deserialization when pr
2026-06-09 CVE-2026-41855 high CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.Mappi
2026-04-28 CVE-2026-40974 medium CVE-2026-40974: Spring Boot's Cassandra auto-configuration does not perform hostname verificatio
2026-04-27 CVE-2026-40971 medium CVE-2026-40971: When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration
2021-05-26 CVE-2021-21985 critical CVE-2021-21985: The vSphere Client (HTML5) contains a remote code execution vulnerability due to
2021-02-24 CVE-2021-21972 critical CVE-2021-21972: The vSphere Client (HTML5) contains a remote code execution vulnerability in a v
2020-10-20 CVE-2020-3992 critical CVE-2020-3992: OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before E
2018-04-11 CVE-2018-1273 critical CVE-2018-1273: Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Command injection in core identity management products allows unrestricted OS command execution, representing a critical security failure with severe fallout for VMware's security posture.
synthesissevere-fallout-0.60
VMware's OpenSLP vulnerability (CVE-2020-3992) is a severe use-after-free flaw allowing remote code execution on the management network, but the provided sources lack direct commentary on VMware's res
synthesissevere-fallout-0.60
VMware faced severe fallout due to actively exploited zero-day vulnerabilities in ESXi, leading to ransomware attacks and urgent patch releases under Broadcom ownership.
synthesissevere-fallout-0.60
NIST and CISA treat CVE-2020-3952 as a high-severity, known exploited vulnerability, indicating severe fallout for VMware's security posture despite no direct press condemnation in the provided source
synthesissevere-fallout-0.60
VMware's critical RCE flaw in vCenter Server was widely condemned by security press and authorities, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout a
synthesissevere-fallout-0.60
VMware's setuid vulnerability in Fusion/VMRC/Horizon Client for Mac was a critical privilege escalation flaw allowing root access, widely flagged as severe by NVD and security press, reflecting poorly
synthesissevere-fallout-0.60
VMware faced severe fallout due to a critical RCE vulnerability in vSphere Client, widely exploited by attackers, with industry press highlighting active weaponization and urgent patching demands.
synthesissevere-fallout-0.60
VMware faced severe fallout for a critical RCE vulnerability in vCenter Server, allowing unrestricted OS command execution via a plugin. The flaw affected multiple versions and was publicly disclosed,
synthesissevere-fallout-0.60
VMware faced severe fallout as active exploitation of its vCenter vulnerabilities was widely reported, indicating a critical failure in security posture and response.
The Hacker News ↗severe-fallout-0.80
The Hacker News reports on actively exploited VMware security flaws, with Broadcom releasing urgent patches.
"Broadcom has released security updates to address three actively exploited security flaws in VMware ESXi, Workstation, and Fusion products that could lead to code execution and information disclosure."
cooey ↗severe-fallout-0.60
Critical setuid privilege escalation flaw in VMware Mac products allowing root access, widely condemned as a severe security oversight.
"VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root."
NVD ↗severe-fallout+0.00
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
cooey ↗severe-fallout-0.80
Severe condemnation of VMware's critical RCE flaw in vCenter Server, with no praise for the vendor's handling.
"VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system."
The Hacker News ↗severe-fallout-0.90
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation."
www.techtimes.com ↗severe-fallout-0.90
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"A China-linked threat actor has spent seven months exploiting a maximum-severity authentication bypass in Oracle's enterprise web middleware — across government and commercial networks in more than 100 countries — and on August 24, 2026, the U.S. Cybersecurity and Infrastructure Security Agency confirmed the ongoing exploitation and imposed its tightest possible emergency patch mandate, ordering e"
CISA ↗severe-fallout-0.90
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"CISA Adds One Known Exploited Vulnerability to Catalog"
www.cvefind.com ↗severe-fallout-0.90
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"CISA Known Exploited Vulnerabilities (KEV) is an initiative that identifies and publishes a list of known exploited vulnerabilities."
app.opencve.io ↗severe-fallout-0.90
Severe condemnation of Oracle's critical flaw, with CISA adding it to the KEV catalog and mandating emergency patches, reflecting severe fallout and a lack of praise for the vendor's handling.
"CVEs in KEV"
cooey ↗severe-fallout-0.60
NIST classifies the vulnerability as high severity with significant confidentiality, integrity, and availability impacts, reflecting severe fallout for VMware's security implementation.
"CVSS 9.8 for CVE-2020-3952... Confidentiality: HIGH Integrity: HIGH Availability: HIGH"
sploitus.com ↗severe-fallout-0.80
Sploitus highlights the exploit's ability to taint the Administrators group, indicating severe fallout for VMware's access control failures.
"LDAP injection in VMware vCenter allows tainting the Administrators group via description attribute."
www.cvefind.com ↗severe-fallout+0.00
CVE Find provides neutral database context without specific sentiment toward VMware.
NIST ↗severe-fallout+0.00
NIST's official site provides neutral institutional context without specific sentiment toward VMware.
xposedornot.com ↗severe-fallout+0.00
XposedOrNot provides neutral breach directory context without specific sentiment toward VMware.
www.wibu.com ↗severe-fallout+0.00
Wibu provides neutral security advisory context without specific sentiment toward VMware.
CISA ↗severe-fallout-0.60
CISA's inclusion of the vulnerability in the KEV catalog indicates severe fallout and government-level concern for VMware's security posture.
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
cooey ↗severe-fallout-0.50
NVD confirms the severity of the file upload vulnerability in VMware vCenter Server, allowing code execution via port 443.
"VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code."
cybersecuritynews.com ↗severe-fallout-0.80
CISA warns of active exploitation of VMware ESXi zero-day vulnerabilities in ransomware attacks, highlighting severe fallout.
"CISA recently confirmed that ransomware groups are actively exploiting CVE-2025-22225, a high-severity VMware ESXi sandbox escape vulnerability."
NIST ↗severe-fallout+0.00
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
NVD ↗severe-fallout+0.00
NVD page provides no direct sentiment toward VMware, only listing the vulnerability database.
www.huntress.com ↗severe-fallout-0.70
Huntress reports on active exploitation of ESXi vulnerabilities in the wild, indicating severe security failures.
"ESXi Exploitation in the Wild"
FEDRAMP CATALOG PRODUCTS · 2
PRODUCTSTATUSIMPACT
VMware Government Services (VGS)AuthorizedHigh
Workspace ONEAuthorizedModerate
Open questions: VMware's current patch SLA and emergency response procedures · VMware's security architecture review and third-party audit results
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:39:39.264522+00:00