PatchSiren

Vmware CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Vmware CVE published 2026-08-27

CVE-2026-59311

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. This vulnerability affects multiple versions of Spring Integration, including 6.4.0-6.4.12, 6.5.0-6.5.10, 7.0.0-7.0.5, and 7.1.0. The issue arises from the way the Zip/UnZip transformer handles output dir [truncated]

MEDIUM VMware CVE published 2026-08-27

CVE-2026-59276

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals()) rather than a constant-time comparison. This could allow potential timing side-channel attacks. Affected versions include Spring Security 5.7.0 - 5.7.25, 5.8.0 - 5.8.27, 6.4.0 - 6.4.18, 6.5.0 - 6.5.11, 7.0.0 - 7.0.6, and 7.1.0. The vulnerability has a CVSS score of 5.9 and a MEDIUM seve [truncated]

MEDIUM VMware CVE published 2026-08-27

CVE-2026-59355

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T10:16:36.197Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Spring Authorization Server versions 1.5.0 through 1.5.7, allowing attackers to craft requests with invalid request_uri and unvalidated redirect_uri parameters, potentially leading [truncated]

HIGH Vmware CVE published 2026-08-27

CVE-2026-47893

A Spring WebFlux application supporting WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. This vulnerability affects multiple versions of Spring Framework, including 7.0.0 - 7.0.8, 6.2.0 - 6.2.19, 6.1.0 - 6.1.28, 6.0.0 - 6.0.30, 5.3.0 - 5.3.49, and 5.2.25.RELEASE and earlier. Organizations should assess their usage and prioritize pa [truncated]

HIGH Vmware CVE published 2026-08-27

CVE-2026-47879

CVE-2026-47879 debrief based on the supplied source corpus. The JsonToGrpcGatewayFilterFactory in Spring Cloud Gateway allows arbitrary Spring Resource locations for defining the proto descriptor, potentially leading to security issues. Affected deployments should assess exposure and verify versions. This vulnerability impacts defenders and administrators of Spring Cloud Gateway deployments, requiring the [truncated]

MEDIUM Vmware CVE published 2026-08-27

CVE-2026-47862

The CVE-2026-47862 vulnerability affects Spring Integration, specifically versions 6.4.0 - 6.4.12, 6.5.0 - 6.5.10, 7.0.0 - 7.0.5, and 7.1.0. An attacker can cause a .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory by setting the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE. Organizations should prioritize patching to prevent [truncated]

MEDIUM VMware CVE published 2026-08-21

CVE-2026-59296

Organizations using micrometer-registry-statsd or micrometer-core, especially those using the Datadog or Etsy flavor of the StatsD registry, or LoggingMeterRegistry, should be aware of this vulnerability. The CVE record describes a vulnerability where using untrusted, non-normalized input as-is for metrics data can lead to injection and spoofing attacks. This vulnerability allows an attacker to break out [truncated]

MEDIUM VMware CVE published 2026-08-21

CVE-2026-59323

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T10:16:38.910Z and has not been modified since then. The vulnerability is a denial of service (DoS) issue in Micrometer Tracing with W3C baggage propagation in the Brave bridge, caused by unbounded object allocation when extracting incoming baggage headers. This occurs when the application uses a [truncated]

CRITICAL VMware CVE published 2026-07-30

CVE-2026-59309

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service, allowing unauthorized access. Affected product deployments should be identified and prioritized for patching. The CVE record was published on 2026-07-30T13:16:53.870Z. The vulnerability has a CVSS score of 9.8 and is considered CRITICAL. VMware vCenter administrators, security teams, and organizations using VMw [truncated]

HIGH VMware CVE published 2026-07-18

CVE-2026-47871

A directory traversal vulnerability exists in VMware Avi Load Balancer, allowing malicious, authenticated network users to perform directory traversal attacks due to flaws in file path validation. This issue affects various versions of VMware Avi Load Balancer, including 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. Users of these versions should apply patches to prevent [truncated]

HIGH VMware CVE published 2026-07-18

CVE-2026-47870

A high-severity privilege escalation vulnerability exists in VMware Avi Load Balancer. A malicious authenticated user with network access may be able to execute remote code. The affected versions are 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. Fixes are available in versions 32.1.2, 31.2.2-2p3, and 30.2.7. This CVE record was published on 2026-07-18T09:17:08.847Z and h [truncated]

HIGH VMware CVE published 2026-07-18

CVE-2026-47869

CVE-2026-47869 is a remote code execution vulnerability in VMware Avi Load Balancer. A malicious authenticated user with network access may be able to inject and execute code. The vulnerability affects multiple versions of the product, including 32.1.1, 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. The vendor has released patches to fix the vulnerability.

HIGH VMware CVE published 2026-07-18

CVE-2026-47867

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. The affected versions are 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), and 22.1.1 through 22.1.7 (fixed in 30.2.7). This vulnerability has a high CVSS score of [truncated]

HIGH VMware CVE published 2026-07-18

CVE-2026-47866

A vulnerability was found in VMware Avi Load Balancer, which could allow a malicious actor on the network to access a limited subset of the Avi Control Plane without proper authorization. This authorization bypass issue has a CVSS score of 8.3, indicating high severity. Affected versions include 32.1.1 (fixed in 32.1.2), 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3), 30.1.1 through 30.2.6 (fixed in 30.2.7), [truncated]

CRITICAL VMware CVE published 2026-07-18

CVE-2026-47865

A critical vulnerability was found in VMware Avi Load Balancer. This vulnerability allows a malicious user with network access to bypass the authentication mechanism and access the Avi Control plane. The affected versions include 31.1.1 through 31.2.2, 30.1.1 through 30.2.6, and 22.1.1 through 22.1.7. Fixed versions are available. This vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. S [truncated]

HIGH Vmware CVE published 2026-06-11

CVE-2026-41856

CVE-2026-41856 is a HIGH severity vulnerability in Spring for GraphQL. The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions include S [truncated]

MEDIUM VMware CVE published 2026-06-10

CVE-2026-47838

CVE-2026-47838 is a medium-severity vulnerability (CVSS Score: 6.8) affecting Spring Security versions 5.7.0 through 5.7.24, 5.8.0 through 5.8.26, 6.3.0 through 6.3.17, 6.4.0 through 6.4.17, and 6.5.0 through 6.5.10. The vulnerability is caused by the SubjectDnX509PrincipalExtractor not correctly handling certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the user [truncated]

HIGH Vmware CVE published 2026-06-09

CVE-2026-41845

CVE-2026-41845 is a high-severity vulnerability in the Spring Framework, a popular Java framework for building enterprise-level applications. The vulnerability has a CVSS score of 7.1 and is classified as HIGH. It was published on 2026-06-09T05:16:36.557Z and modified on 2026-06-11T16:12:37.023Z.

HIGH VMware CVE published 2026-06-08

CVE-2026-41724

CVE-2026-41724 is a HIGH severity vulnerability in VMware Cloud Foundation Operations. A malicious actor with privileges to create policies, views, or text-widgets may be able to inject scripts to perform administrative actions.

HIGH VMware CVE published 2026-06-08

CVE-2026-41723

CVE-2026-41723 is a HIGH severity vulnerability in VMware Cloud Foundation Operations. A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform administrative actions in VMware Cloud Foundation Operations. The vulnerability has a CVSS score of 8 and was first published on [cve-org](https://www.cve.org/CVERecord?id=CVE-2026-41723).

HIGH VMware CVE published 2026-06-08

CVE-2026-41722

CVE-2026-41722 is a HIGH severity vulnerability in VMware Cloud Foundation Operations. A malicious actor with privileges to create policies, views, or text-widgets may be able to inject scripts to perform administrative actions.

HIGH VMware CVE published 2026-05-15

CVE-2026-41702

A Time-of-check Time-of-use (TOCTOU) vulnerability in VMware Fusion allows local privilege escalation to root. The flaw exists in a SETUID binary operation, where a race condition between checking a resource's state and using it can be exploited by an attacker with local non-administrative access. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates high impact across confidentiality, integ [truncated]

MEDIUM Vmware CVE published 2026-04-28

CVE-2026-40974

CVE-2026-40974 is a medium-severity vulnerability in Spring Boot's Cassandra auto-configuration. The vulnerability occurs when establishing an SSL connection to Cassandra without performing hostname verification. Affected versions include Spring Boot 4.0.0–4.0.5, 3.5.0–3.5.13, 3.4.0–3.4.15, 3.3.0–3.3.18, and 2.7.0–2.7.32. Fixes are available in versions 4.0.6, 3.5.14, 3.4.16, 3.3.19, and 2.7.33.

MEDIUM VMware CVE published 2026-04-27

CVE-2026-40971

CVE-2026-40971 is a medium-severity vulnerability in Spring Boot's RabbitMQ auto-configuration. When configured to use an SSL bundle, hostname verification is not performed when connecting to the RabbitMQ broker. This oversight could allow for man-in-the-middle attacks, potentially leading to data breaches or unauthorized access. Affected versions include Spring Boot 4.0.0–4.0.5 and 3.5.0–3.5.13; fixes ar [truncated]

HIGH Vmware CVE published 2026-04-10

CVE-2026-22750

CVE-2026-22750 was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-22750) with a CVSS score of 7.5 and HIGH severity. The vulnerability affects Spring Cloud Gateway, specifically when configuring SSL bundles using the configuration property `spring.ssl.bundle`. The configuration was silently ignored, and the default SSL configuration was used instead. The CVE was modified on [cveMo [truncated]

HIGH Vmware CVE published 2026-03-27

CVE-2026-22742

CVE-2026-22742 describes a server-side request forgery (SSRF) issue in Spring AI's spring-ai-bedrock-converse component. When BedrockProxyChatModel processes multimodal messages that include user-supplied media URLs, insufficient validation can let an attacker cause the server to send HTTP requests to unintended destinations. The issue is rated HIGH with CVSS 8.6 and affects Spring AI versions from 1.0.0 [truncated]

CRITICAL Vmware CVE published 2026-03-27

CVE-2026-22738

CVE-2026-22738 is a critical Spring AI vulnerability in SimpleVectorStore. If an application uses user-supplied input as a filter expression key, a malicious actor may be able to trigger SpEL injection and execute arbitrary code. NVD lists this as CVSS 9.8, with network attack vector, no privileges required, and no user interaction.

HIGH VMware CVE published 2026-02-20

CVE-2026-2818

CVE-2026-2818 is a high-severity zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality. This vulnerability allows attackers to write files outside the intended extraction directory and appears to be susceptible on Windows OS only. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. The CVE was published on 2026-02-20T17:25:57.980Z and last modified on [truncated]

HIGH VMware CVE published 2025-07-31

CVE-2025-41239

CVE-2025-41239 is a high-severity information disclosure vulnerability in VMware vSockets caused by uninitialized memory in VMware ESXi, Workstation, Fusion, and VMware Tools. In the Rockwell Automation advisory, several VMware-dependent offerings are affected, including Industrial Data Center (IDC) with VMware, VersaVirtual Appliance (VVA) with VMware, Threat Detection Managed Services (TDMS) with VMware [truncated]

CRITICAL VMware CVE published 2025-07-31

CVE-2025-41238

CVE-2025-41238 is a critical VMware vulnerability affecting the Paravirtualized SCSI (PVSCSI) controller in ESXi, Workstation, and Fusion. According to the advisory corpus, successful exploitation can cause an out-of-bounds write and lead to code execution on the host. Rockwell Automation’s CSAF advisory maps the issue to multiple Rockwell offerings that use VMware components and directs customers to VMwa [truncated]