These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2025-22226 is a VMware information disclosure vulnerability affecting ESXi, Workstation, and Fusion. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-04, so defenders should treat it as an urgent remediation item rather than a routine patch task. The supplied corpus does not provide affected versions, a CVSS score, or a detailed attack path, so validation should start with the v [truncated]
CVE-2025-22225 is a VMware ESXi arbitrary write vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-03-04. The KEV entry marks it as having known ransomware campaign use, which makes it a high-priority remediation item for any organization running ESXi. CISA’s required action is to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discon [truncated]
CVE-2025-22224 is a VMware ESXi and Workstation time-of-check to time-of-use (TOCTOU) race condition vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-03-04. Because it is in KEV, defenders should treat it as a priority issue and follow vendor mitigation guidance and CISA’s required actions without delay.
CVE-2024-38813 is an official VMware vCenter Server privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-11-20. The supplied timeline also shows a remediation due date of 2024-12-11. Because the source corpus provides limited technical detail, the safest response is to treat affected vCenter Server deployments as a high-priority exposure and follow vend [truncated]
CVE-2024-38812 is a VMware vCenter Server heap-based buffer overflow vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-11-20. Because it is listed in KEV, defenders should treat it as actively exploited and prioritize vendor-directed mitigations or remediation immediately. CISA’s due date for remediation in the KEV catalog is 2024-12-11.
CVE-2024-37085 is a VMware ESXi authentication bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2024-07-30. The KEV entry marks it as having known ransomware campaign use, which makes this a high-priority issue for any organization running ESXi. The supplied authoritative sources direct defenders to apply vendor mitigations or discontinue use of the product if mitigat [truncated]
CVE-2022-22948 is described as an incorrect default file permissions issue in VMware vCenter Server. CISA includes it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as a priority remediation item and follow VMware's guidance without delay.
CVE-2023-34048 affects VMware vCenter Server and is described as an out-of-bounds write vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-22, with remediation due by 2024-02-12, so affected environments should treat it as a priority issue and follow vendor guidance promptly.
CVE-2023-20867 is an authentication bypass vulnerability in VMware Tools. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-23, which means it should be treated as a prioritized remediation item. The supplied corpus does not include exploit mechanics or affected-version details, so the safest response is to follow VMware’s update guidance and verify that VMware Tools is fully patched.
CVE-2023-20887 is a command injection vulnerability affecting VMware Aria Operations for Networks. CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-22 and set a remediation due date of 2023-07-13, which makes this a high-priority issue for affected deployments.
CVE-2022-22947 is a VMware Spring Cloud Gateway code injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-05-16. Because it is listed in KEV, defenders should treat it as actively exploited and prioritize remediation using vendor guidance.
CVE-2022-22960 is a VMware Multiple Products privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-15. Because it is in KEV, defenders should treat it as a priority issue and apply VMware updates per vendor instructions as soon as possible.
CVE-2022-22954 is a VMware Workspace ONE Access and Identity Manager server-side template injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-14. Because it is confirmed in KEV and marked as having known ransomware campaign use, organizations running the affected VMware products should treat it as a high-priority remediation item and follow vendor update guida [truncated]
CVE-2022-22965 is a VMware Spring Framework remote code execution vulnerability affecting JDK 9+ environments. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-04, which indicates confirmed real-world exploitation and makes prompt remediation important.
CVE-2018-6961 is a VMware SD-WAN Edge by VeloCloud command injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is in the KEV catalog, defenders should treat it as actively exploited and prioritize vendor-guided remediation for any exposed VMware SD-WAN Edge deployments.
CVE-2021-21973 is a VMware vCenter Server and Cloud Foundation server-side request forgery (SSRF) vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not just that the issue exists, but that it is considered known exploited and should be treated as a high-priority patching item. CISA’s KEV entry directs organizations to apply updates per vendor [truncated]
CVE-2021-21975 is a VMware server-side request forgery (SSRF) issue affecting the vRealize Operations Manager API. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-18 and marked it as having known ransomware campaign use. The listed required action is to apply updates per vendor instructions.
CVE-2021-22017 is an improper access control issue in VMware vCenter Server that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known to be exploited, organizations running vCenter Server should treat it as a high-priority remediation item and apply VMware’s updates as soon as possible.
CVE-2021-22005 is a VMware vCenter Server file upload vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The public KEV record marks it as known exploited and notes known ransomware campaign use, which makes this a high-priority defensive issue. The KEV catalog entry also sets a remediation due date of 2021-11-17 and directs defenders to apply updates per vendor instructions.
CVE-2021-21985 is an improper input validation vulnerability in VMware vCenter Server. CISA lists it in the Known Exploited Vulnerabilities catalog and notes known ransomware campaign use, which raises the defensive priority for exposed or widely relied-on vCenter deployments. The practical response is to apply vendor updates per VMware guidance as soon as possible.
CVE-2021-21972 is a VMware vCenter Server remote code execution vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. CISA also marks it as associated with known ransomware campaign use, which makes this a high-priority remediation item for any environment running vCenter Server.
CVE-2020-4006 is a command injection vulnerability affecting multiple VMware products and is listed in CISA’s Known Exploited Vulnerabilities catalog, which makes it a clear defensive priority for organizations running VMware software. The official KEV entry directs defenders to apply updates per vendor instructions. Because the source corpus does not provide affected versions or product-specific details, [truncated]
CVE-2020-3992 is a VMware ESXi vulnerability in OpenSLP described by CISA as a use-after-free issue. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed exploitation in the wild. CISA also marks it as having known ransomware campaign use, so ESXi environments should treat it as an urgent remediation item and follow VMware’s update guidance.
CVE-2020-3952 is a VMware vCenter Server information disclosure vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is in KEV, defenders should treat it as a high-priority remediation item and apply vendor updates per VMware instructions.
CVE-2020-3950 is a VMware Multiple Products privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The available official record indicates active concern from a known-exploitation authority, so organizations running VMware products should treat vendor updates as a priority and verify exposure quickly.
CVE-2019-5544 is a VMware OpenSLP heap-based buffer overflow affecting VMware ESXi and Horizon DaaS. CISA has listed it in the Known Exploited Vulnerabilities catalog, and the KEV entry indicates known ransomware campaign use. That combination makes it a high-priority remediation item for any exposed VMware environment.