Exploited CVEs / By vendor / VMware

VMware vulnerabilities actively exploited

26 VMware CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2025-22224 (ESXi and Workstation, added 2025-03-04). 9 of the 26 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

26 exploited CVEs9 ransomware-linked
Senserva AI Opinion and rich prompt for VMware exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

vCenter Server: 9 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-38812vCenter Server2024-11-20CVSS 9.8, EPSS 55%
CVE-2024-38813vCenter Server2024-11-20CVSS 9.8, EPSS 17%
CVE-2022-22948vCenter Server2024-07-17CVSS 6.5, EPSS 13%
CVE-2023-34048vCenter Server2024-01-22CVSS 9.8, EPSS 99%
CVE-2021-22017vCenter Server2022-01-10CVSS 5.3, EPSS 49%
CVE-2020-3952vCenter Server2021-11-03CVSS 9.8, EPSS 90%
CVE-2021-21972vCenter Server2021-11-03ransomware, CVSS 9.8, EPSS 100%
CVE-2021-21985vCenter Server2021-11-03ransomware, CVSS 9.8, EPSS 100%
CVE-2021-22005vCenter Server2021-11-03ransomware, CVSS 9.8, EPSS 100%

ESXi: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2025-22225ESXi2025-03-04ransomware, CVSS 8.2, EPSS 1%
CVE-2024-37085ESXi2024-07-30ransomware, CVSS 7.2, EPSS 27%
CVE-2020-3992ESXi2021-11-03ransomware, CVSS 9.8, EPSS 83%

Multiple Products: 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2022-22960Multiple Products2022-04-15CVSS 7.8, EPSS 36%
CVE-2020-3950Multiple Products2021-11-03CVSS 7.8, EPSS 7%
CVE-2020-4006Multiple Products2021-11-03CVSS 9.1, EPSS 17%

Other VMware products

CVEProductAdded to KEVSignals
CVE-2025-22224ESXi and Workstation2025-03-04CVSS 8.2, EPSS 2%
CVE-2025-22226ESXi, Workstation, and Fusion2025-03-04CVSS 6.0, EPSS 2%
CVE-2023-20867Tools2023-06-23CVSS 3.9, EPSS 14%
CVE-2023-20887Aria Operations for Networks2023-06-22CVSS 9.8, EPSS 98%
CVE-2022-22947Spring Cloud Gateway2022-05-16CVSS 10.0, EPSS 98%
CVE-2022-22954Workspace ONE Access and Identity Manager2022-04-14ransomware, CVSS 9.8, EPSS 100%
CVE-2022-22965Spring Framework2022-04-04CVSS 9.8, EPSS 100%
CVE-2018-6961SD-WAN Edge2022-03-25CVSS 8.1, EPSS 86%
CVE-2021-21973vCenter Server and Cloud Foundation2022-03-07CVSS 5.3, EPSS 88%
CVE-2021-21975vRealize Operations Manager API2022-01-18ransomware, CVSS 7.5, EPSS 78%
CVE-2019-5544VMware ESXi and Horizon DaaS2021-11-03ransomware, CVSS 9.8, EPSS 97%

Common questions about exploited VMware CVEs

Which VMware vulnerabilities are actively exploited?

As of August 2026, 26 VMware CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are vCenter Server (9), ESXi (3), Multiple Products (3). 9 are linked to ransomware campaigns.

What is the newest exploited VMware CVE?

CVE-2025-22224, affecting ESXi and Workstation, added to the CISA KEV catalog on 2025-03-04. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these VMware CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited VMware CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest VMware KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.