CVE-2026-41709
- EPSS 0.38%
- Veröffentlicht 30.07.2026 12:45:02
- Zuletzt bearbeitet 30.07.2026 19:07:59
VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.
CVE-2026-41703
- EPSS 0.56%
- Veröffentlicht 30.07.2026 12:39:02
- Zuletzt bearbeitet 30.07.2026 16:17:11
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (Do...
CVE-2026-47876
- EPSS 0.28%
- Veröffentlicht 30.07.2026 12:31:52
- Zuletzt bearbeitet 30.07.2026 14:16:58
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code o...
CVE-2026-59309
- EPSS 0.74%
- Veröffentlicht 30.07.2026 12:19:52
- Zuletzt bearbeitet 30.07.2026 16:17:15
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
CVE-2026-59310
- EPSS 2.41%
- Veröffentlicht 30.07.2026 12:19:25
- Zuletzt bearbeitet 19.08.2026 04:17:24
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVE-2026-22721
- EPSS 0.69%
- Veröffentlicht 25.02.2026 20:00:15
- Zuletzt bearbeitet 04.03.2026 15:54:26
VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2...
- EPSS 0.41%
- Veröffentlicht 25.02.2026 19:33:14
- Zuletzt bearbeitet 04.03.2026 15:55:32
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-20...
CVE-2026-22719
- EPSS 17.42%
- Veröffentlicht 25.02.2026 19:18:59
- Zuletzt bearbeitet 04.03.2026 15:08:13
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product...
CVE-2025-41252
- EPSS 0.88%
- Veröffentlicht 29.09.2025 19:15:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates...
CVE-2025-41251
- EPSS 1.02%
- Veröffentlicht 29.09.2025 19:15:35
- Zuletzt bearbeitet 15.04.2026 00:35:42
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force r...