Vendor
VMware vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 179 vulnerabilities in VMware: 0 in the last 7 days and 54 in the last 90 days, 39 of them critical and 28 exploited in the wild. The most recent, CVE-2026-75516, was published on 16 September 2026. 25 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 54
- Critical, all time
- 39
- Exploited in the wild
- 28
About VMware
Software company providing virtualization, cloud computing, and enterprise infrastructure solutions.
VMware technologies
- VMware Spring Framework24
- VMware Cloud Foundation21
- VMware Spring Security15
- VMware Spring AI14
- VMware ESXi11
- VMware Spring Boot11
- VMware Avi Load Balancer7
- VMware Spring for GraphQL7
- VMware Spring Integration7
- VMware vSphere Foundation7
- VMware Spring Web Services7
- VMware Fusion6
- VMware Spring Data REST6
- VMware Spring Cloud Config5
- VMware Spring Cloud Function5
- VMware Workstation5
- VMware Reactor Netty4
- VMware Spring AMQP4
- VMware Spring Cloud Gateway4
- VMware Cloud Foundation Operations3
- VMware Identity Manager3
- VMware Spring Authorization Server3
- VMware Spring Cloud Stream3
- VMware Spring for Apache Kafka3
- VMware Workspace ONE Access3
Latest VMware vulnerabilities
- CVE-2026-75516: The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes…highCVSS 8.7EPSS 0.5%
- CVE-2026-59320: Spring AMQP link credit exhaustion in error handlermediumCVSS 6.5EPSS 0.4%
- CVE-2026-59319: Spring AI RedisChatMemoryRepository RediSearch injection in findByMetadata()mediumCVSS 4.3EPSS 0.3%
- CVE-2026-59316: Spring Authorization Server XSS in default consent pagehighCVSS 8.2EPSS 0.3%
- CVE-2026-59313: Spring Framework stream corruption in Server-Sent EventscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-59305: Spring Cloud Stream partition interceptor improper message handlinglowCVSS 3.1EPSS 0.2%
- CVE-2026-59304: VMware Spring Cloud Stream improper content type caching in AvrolowCVSS 3.1EPSS 0.2%
- CVE-2026-59302: Spring Cloud Stream information disclosure via logginglowCVSS 3.1EPSS 0.2%
- CVE-2026-59301: Spring Cloud Function Azure sensitive data logginglowCVSS 3.1EPSS 0.2%
- CVE-2026-59300: Spring Cloud Function sensitive data logging in AWS integrationlowCVSS 3.1EPSS 0.2%
- CVE-2026-59294: Spring AI path traversal in ResourceCacheServicemediumCVSS 5.9EPSS 0.4%
- CVE-2026-59292: Spring Integration insecure temporary file permissions in metadata storelowCVSS 3.2EPSS 0.1%
- CVE-2026-59291: Spring Cloud Function arbitrary file read and SSRFlowCVSS 2EPSS 0.3%
- CVE-2026-59289: Spring for GraphQL Spring Data pagination denial of servicehighCVSS 7.5EPSS 0.5%
- CVE-2026-59287: Spring for GraphQL denial of service with WebSocket keepAlivemediumCVSS 5.9EPSS 0.4%
- CVE-2026-59286: Spring for GraphQL missing Subresource Integrity on CDN-loaded JavaScripthighCVSS 8.1EPSS 0.3%
- CVE-2026-59285: Spring for GraphQL unsafe deserialization in paginationhighCVSS 8.1EPSS 0.4%
- CVE-2026-59277: Spring Security InetAddressMatchers IP classification bypasslowCVSS 3.7EPSS 0.3%
- CVE-2026-59276: Spring Security timing attack on security-sensitive string comparisonmediumCVSS 5.9EPSS 0.3%
- CVE-2026-59354: Spring Security OAuth2 Authorization Server metadata validation in Dynamic Client RegistrationcriticalCVSS 9.6EPSS 0.5%
- CVE-2026-59275: Spring AMQP malicious message denial of servicemediumCVSS 6.6EPSS 0.4%
- CVE-2026-59274: Spring Integration UnZipTransformer denial-of-service via zip bombmediumCVSS 6.5EPSS 0.4%
- CVE-2026-59271: Spring AMQP RabbitMQ management password disclosure in exception messagemediumCVSS 5.3EPSS 0.3%
- CVE-2026-59270: Spring Security embedded UnboundID LDAP server authentication bypasscriticalCVSS 9.4EPSS 0.4%
- CVE-2026-47893: Spring Framework information disclosure in WebSocket exception handlinghighCVSS 7.5EPSS 0.4%
Most severe VMware vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2022-22947: VMware Spring Cloud Gateway Code Injection Vulnerabilitycriticalexploited in the wildCVSS 10
- CVE-2024-37079: Broadcom VMware vCenter Server out-of-bounds write in DCERPC protocolcriticalexploited in the wildCVSS 9.8EPSS 82.0%
- CVE-2026-59310: VMware vCenter directory traversal in Syslog servercriticalexploited in the wildCVSS 9.8EPSS 2.6%
- CVE-2024-38812: VMware vCenter Server Heap-Based Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2024-38813: VMware vCenter Server Privilege Escalation Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-34048: VMware vCenter Server Out-of-Bounds Write Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2023-20887: Vmware Aria Operations for Networks Command Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-22954: VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2022-22965: Spring Framework JDK 9+ Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2021-21972: VMware vCenter Server Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 7 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 5 | 3 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 3 | 0 | |
| 24 Aug 2026 | 37 | 4 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/vmware.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "VMware vulnerabilities", https://junglewise.ai/threats/vendors/vmware, 26 September 2026.