VMware (Broadcom) vCenter Server
Our sources currently list 79 known vulnerabilities affecting VMware (Broadcom) vCenter Server. 15 are rated critical severity. 11 of 79 are actively exploited according to CISA, the most recent added 23 January 2026.
Last updated: 22 July 2026, 20:34 AEST
No current ASD advisory names this product.That describes the Australian Signals Directorate’s publication record — it is not a statement that this product is free of vulnerabilities. See the list below.
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2021-21985 | Critical (9.8) | Actively exploited · ransomware | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe… | |
| CVE-2021-22005 | Critical (9.8) | Actively exploited · ransomware | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is… | |
| CVE-2021-21972 | Critical (9.8) | Actively exploited · ransomware | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex… | |
| CVE-2023-34048 | Critical (9.8) | Actively exploited | vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou… | |
| CVE-2020-3952 | Critical (9.8) | Actively exploited | Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access co… | |
| CVE-2021-21973 | Medium (5.3) | Actively exploited | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with networ… | |
| CVE-2024-38812 | Critical (9.8) | Actively exploited | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vul… | |
| CVE-2021-22017 | Medium (5.3) | Actively exploited | Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Serve… | |
| CVE-2024-37079 | Critical (9.8) | Actively exploited | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnera… | |
| CVE-2024-38813 | High (7.5) | Actively exploited | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to r… | |
| CVE-2022-22948 | Medium (6.5) | Actively exploited | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may … | |
| CVE-2015-2342 | Critical (10.0) | Elevated likelihood (89%) | The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attacker… | |
| CVE-2022-31698 | Medium (5.3) | Elevated likelihood (48%) | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this i… | |
| CVE-2023-20894 | High (8.1) | Elevated likelihood (34%) | The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may tr… | |
| CVE-2022-31680 | Critical (9.1) | Elevated likelihood (33%) | The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit thi… | |
| CVE-2021-21986 | Critical (9.8) | Elevated likelihood (13%) | The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Clo… | |
| CVE-2024-37080 | Critical (9.8) | Elevated likelihood (12%) | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnera… | |
| CVE-2021-22048 | High (8.8) | No exploitation reported | The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative … | |
| CVE-2009-2698 | High (7.8) | No exploitation reported | The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a d… | |
| CVE-2021-22006 | High (7.5) | No exploitation reported | The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server ma… | |
| CVE-2024-37081 | High (7.8) | No exploitation reported | The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may … | |
| CVE-2021-21980 | High (7.5) | No exploitation reported | The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this… | |
| CVE-2014-4241 | Medium (4.3) | No exploitation reported | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect integrity via vectors related … | |
| CVE-2015-1047 | Medium (5.0) | No exploitation reported | vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message. | |
| CVE-2013-1405 | Critical (10.0) | No exploitation reported | VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 before Update 3a, VMware VI-Client… | |
| CVE-2024-22274 | High (7.2) | No exploitation reported | The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this i… | |
| CVE-2017-4927 | High (7.5) | No exploitation reported | VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service. | |
| CVE-2020-3976 | Medium (5.3) | No exploitation reported | VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be … | |
| CVE-2017-4919 | Critical (9.0) | No exploitation reported | VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authentic… | |
| CVE-2013-5971 | Medium (6.8) | No exploitation reported | Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via … | |
| CVE-2021-22015 | High (7.8) | No exploitation reported | The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administr… | |
| CVE-2016-5331 | Medium (6.1) | No exploitation reported | CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attack… | |
| CVE-2016-7459 | High (7.7) | No exploitation reported | VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Conten… | |
| CVE-2019-5532 | High (7.7) | No exploitation reported | VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in pl… | |
| CVE-2017-4923 | Critical (9.8) | No exploitation reported | VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Serve… | |
| CVE-2023-20892 | High (8.1) | No exploitation reported | The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network acce… | |
| CVE-2013-1659 | High (7.6) | No exploitation reported | VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Ne… | |
| CVE-2009-2416 | Medium (6.5) | No exploitation reported | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (ap… | |
| CVE-2021-22008 | High (7.5) | No exploitation reported | The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit t… | |
| CVE-2021-22049 | Critical (9.8) | No exploitation reported | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to … | |
| CVE-2017-4921 | High (8.8) | No exploitation reported | VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploi… | |
| CVE-2021-22013 | High (7.5) | No exploitation reported | The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443… | |
| CVE-2021-22010 | High (7.5) | No exploitation reported | The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create … | |
| CVE-2019-5534 | High (7.7) | No exploitation reported | VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an… | |
| CVE-2021-22019 | High (7.5) | No exploitation reported | The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this i… | |
| CVE-2021-22014 | High (7.2) | No exploitation reported | The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to p… | |
| CVE-2021-22009 | High (7.5) | No exploitation reported | The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploi… | |
| CVE-2016-2076 | High (7.6) | No exploitation reported | Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2… | |
| CVE-2021-22012 | High (7.5) | No exploitation reported | The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter… | |
| CVE-2023-20895 | High (8.1) | No exploitation reported | The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigg… |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
11 of these are being actively exploited right now.
Our Newcastle team can audit your VMware (Broadcom) estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
