Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

VMware — Vulnerabilities & Security Advisories 240

Browse all 240 CVE security advisories affecting VMware. AI-powered Chinese analysis, POCs, and references for each vulnerability.

VMware operates as a leading provider of cloud computing and virtualization platforms, enabling enterprises to manage data centers and deploy software-defined infrastructure. With 219 recorded CVEs, its attack surface reflects the complexity of managing hypervisors and management interfaces. Historically, vulnerabilities have frequently involved remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation or authentication bypasses in web-based management consoles. Notable incidents include critical flaws in vCenter Server and ESXi that allowed attackers to gain unauthorized administrative access or execute arbitrary commands on host systems. These exploits underscore the risks associated with centralized management tools, where a single compromise can impact entire virtualized environments. The high volume of vulnerabilities highlights the necessity for rigorous patch management and secure configuration practices to mitigate potential breaches in enterprise infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-59296 Micrometer StatsD and Logging meter registries line-protocol and log injection vulnerability — Spring Micrometer 5.9 Medium 2026-08-21
CVE-2026-59323 Micrometer Tracing Brave Bridge W3C Baggage propagation DoS vulnerability — Spring 5.3 Medium 2026-08-21
CVE-2026-41709 ESX insufficient logging vulnerability — Cloud Foundation CWE-778 2.7 Low 2026-07-30
CVE-2026-41703 Out-of-bounds read vulnerability — Cloud Foundation CWE-125 7.6 High 2026-07-30
CVE-2026-47876 VMXNET3 out-of-bounds write vulnerability — Cloud Foundation CWE-787 9.3 Critical 2026-07-30
CVE-2026-59309 vCenter authentication-bypass vulnerability — Cloud Foundation CWE-303 9.8 Critical 2026-07-30
CVE-2026-59310 vCenter directory-traversal vulnerability — Cloud Foundation CWE-22 9.8 Critical 2026-07-30
CVE-2026-47871 VMware Avi Load Balancer Directory Traversal Vulnerability — Avi Load Balancer CWE-22 8.8 High 2026-07-18
CVE-2026-47870 VMware Avi Load Balancer Privilege Escalation Vulnerability — Avi Load Balancer CWE-269 7.1 High 2026-07-18
CVE-2026-47869 VMware Avi Load Balancer Remote Code Execution Vulnerability — Avi Load Balancer CWE-94 8.7 High 2026-07-18
CVE-2026-47868 VMware Avi Load Balancer Local Privilege Escalation Vulnerability — Avi Load Balancer CWE-269 7.8 High 2026-07-18
CVE-2026-47867 VMware Avi Load Balancer Remote Code Execution Vulnerability — Avi Load Balancer CWE-94 8.7 High 2026-07-18
CVE-2026-47866 VMware Avi Load Balancer Authorization Bypass Vulnerability — Avi Load Balancer CWE-863 8.3 High 2026-07-18
CVE-2026-47865 VMware Avi Load Balancer Authentication Bypass Vulnerability — Avi Load Balancer CWE-287 9.8 Critical 2026-07-18
CVE-2026-59269 Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries — Pinniped 3.8 Low 2026-07-09
CVE-2026-41724 VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) — VCF operations 8.0 High 2026-06-08
CVE-2026-41723 VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) — VCF operations 8.0 High 2026-06-08
CVE-2026-41722 VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) — VCF operations 8.0 High 2026-06-08
CVE-2026-41702 TOCTOU local privilege escalation vulnerability — Fusion CWE-367 7.8 High 2026-05-15
CVE-2026-41713 Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor — Spring AI CWE-1336 8.2 High 2026-05-12
CVE-2026-41712 ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage — Spring AI 7.5 High 2026-05-12
CVE-2026-22745 CVE-2026-22745 : Denial of service in static resource handling on Windows platforms — Spring Framework CWE-400 5.3 Medium 2026-04-29
CVE-2026-22741 Static resource cache poisoning in Spring MVC and WebFlux — Spring Framework CWE-524 3.1 Low 2026-04-29
CVE-2026-22740 Spring Framework DoS with Multipart Temp Files in WebFlux — Spring Framework CWE-400 6.5 Medium 2026-04-29
CVE-2026-40966 VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration — Spring AI CWE-284 5.9 Medium 2026-04-28
CVE-2026-22750 SSL bundle configuration silently bypassed in Spring Cloud Gateway — Spring Cloud Gateway 7.5 High 2026-04-10
CVE-2026-22732 Under Some Conditions Spring Security HTTP Headers Are not Written — Spring Security 9.1 Critical 2026-03-19
CVE-2026-22729 CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter — Spring AI 8.6 High 2026-03-18
CVE-2026-22730 CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter — Spring AI 8.8 High 2026-03-18
CVE-2026-22717 VMware Workstation out-of-bound read vulnerability — Workstation CWE-125 2.7 Low 2026-02-27

This page lists every published CVE security advisory associated with VMware. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.