Vmware Vcenter vulnerabilities
9 known vulnerabilities affecting vmware/vcenter.
Total CVEs
9
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH2MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-59310P1CRITICALCVSS 9.8KEVPoCRansomware≥ 9.1.x.x, < 9.1.0.0300≥ 9.0.x.x, < 9.0.2.0100+1 more2026-07-30
CVE-2026-59310 [CRITICAL] CWE-22 CVE-2026-59310: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
nvd
CVE-2026-59309P1CRITICALCVSS 9.8Exploited≥ 9.1.x.x, < 9.1.0.0300≥ 9.0.x.x, < 9.0.2.0100+1 more2026-07-30
CVE-2026-59309 [CRITICAL] CWE-303 CVE-2026-59309: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A ma
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
nvd
CVE-2025-41250P3HIGHCVSS 8.5≥ 8.0, < 8.0 U3g≥ 7.0, < 7.0 U3w2025-09-29
CVE-2025-41250 [HIGH] CWE-77 CVE-2025-41250: VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administr
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
nvd
CVE-2009-0778P4HIGHCVSS 7.1v4.02009-03-12
CVE-2009-0778 [HIGH] CVE-2009-0778: The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a ro
The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage)
nvd
CVE-2011-0426P4MEDIUMCVSS 4.3v4.0v4.12011-05-09
CVE-2011-0426 [MEDIUM] CWE-22 CVE-2011-0426: Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 be
Directory traversal vulnerability in vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, and VMware VirtualCenter 2.5 before Update 6a, allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2011-1789P4MEDIUMCVSS 5.0v4.0v4.12011-05-09
CVE-2011-1789 [MEDIUM] CWE-310 CVE-2011-1789: The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before U
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software distribution via a Trojan horse install
nvd
CVE-2009-3731P4MEDIUMCVSS 4.3v4.02009-12-16
CVE-2009-3731 [MEDIUM] CWE-79 CVE-2009-3731: Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCent
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and
nvd
CVE-2025-41241P4MEDIUMCVSS 4.4≥ 8.0, < 8.0 U3g≥ 7.0, < 7.0 U3v2025-07-29
CVE-2025-41241 [MEDIUM] CWE-754 CVE-2025-41241: VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated th
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.
nvd
CVE-2011-1788P4LOWCVSS 2.1v4.0v4.12011-05-09
CVE-2011-1788 [LOW] CWE-200 CVE-2011-1788: vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to d
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
nvd