cbcvebase.

Vmware Vsphere Foundation vulnerabilities

7 known vulnerabilities affecting vmware/vsphere_foundation.

Total CVEs
7
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-59310P1CRITICALCVSS 9.8KEVPoCRansomwarev9.1.x.xv9.0.x.x2026-07-30
CVE-2026-59310 [CRITICAL] CWE-22 CVE-2026-59310: VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
nvd
CVE-2026-59309P1CRITICALCVSS 9.8Exploitedv9.1.x.xv9.0.x.x2026-07-30
CVE-2026-59309 [CRITICAL] CWE-303 CVE-2026-59309: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A ma VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
nvd
CVE-2026-47876P3CRITICALCVSS 9.3v9.1.x.xv9.0.x.x2026-07-30
CVE-2026-47876 [CRITICAL] CWE-787 CVE-2026-47876: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A m VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
nvd
CVE-2025-41237P3CRITICALCVSS 9.3v9.0.0.02025-07-15
CVE-2025-41237 [CRITICAL] CWE-787 CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communica VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitat
nvd
CVE-2025-41250P3HIGHCVSS 8.5≥ 9.x.x.x, < 9.0.1.02025-09-29
CVE-2025-41250 [HIGH] CWE-77 CVE-2025-41250: VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administr VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
nvd
CVE-2026-41703P3HIGHCVSS 7.6v9.1.x.xv9.0.x.x2026-07-30
CVE-2026-41703 [HIGH] CWE-125 CVE-2026-41703: VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor w VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restri
nvd
CVE-2026-41709P4LOWCVSS 2.7v9.1.x.xv9.0.x.x2026-07-30
CVE-2026-41709 [LOW] CWE-778 CVE-2026-41709: VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit t VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
nvd
Vmware Vsphere Foundation vulnerabilities | cvebase