{"schema_version":1,"title":"VMware vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 206 vulnerabilities in VMware: 27 in the last 7 days and 81 in the last 90 days, 39 of them critical and 28 exploited in the wild. The most recent, CVE-2026-67421, was published on 25 September 2026. 25 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/vmware","json_url":"https://junglewise.ai/threats/vendors/vmware.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/vmware","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":63,"all_time":206,"critical":39,"exploited":28,"last_7_days":27,"last_30_days":46,"last_90_days":81,"last_365_days":180},"latest":[{"cve":"CVE-2026-67421","slug":"cve-2026-67421-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3","title":"RabbitMQ Management XSS via queue name in OAuth UI","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:14.12+00:00","url":"https://junglewise.ai/threats/cve-2026-67421-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3"},{"cve":"CVE-2026-67413","slug":"cve-2026-67413-rabbitmq-is-a-messaging-and-streaming-broker-from-4-0-0-until-4-0","title":"RabbitMQ JMS topic exchange denial of service via regex wildcard expansion","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:13.547+00:00","url":"https://junglewise.ai/threats/cve-2026-67413-rabbitmq-is-a-messaging-and-streaming-broker-from-4-0-0-until-4-0"},{"cve":"CVE-2026-67412","slug":"cve-2026-67412-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-4","title":"RabbitMQ Federation upstream authorization bypass","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:13.393+00:00","url":"https://junglewise.ai/threats/cve-2026-67412-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-4"},{"cve":"CVE-2026-67408","slug":"cve-2026-67408-rabbitmq-is-a-messaging-and-streaming-broker-from-4-1-0-until-4-3","title":"RabbitMQ denial of service in Stream Management super-stream binding","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:12.767+00:00","url":"https://junglewise.ai/threats/cve-2026-67408-rabbitmq-is-a-messaging-and-streaming-broker-from-4-1-0-until-4-3"},{"cve":"CVE-2026-67407","slug":"cve-2026-67407-rabbitmq-is-a-messaging-and-streaming-broker-from-4-0-0-until-4-3","title":"RabbitMQ MQTT topic permission bypass in regex escaping","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:12.62+00:00","url":"https://junglewise.ai/threats/cve-2026-67407-rabbitmq-is-a-messaging-and-streaming-broker-from-4-0-0-until-4-3"},{"cve":"CVE-2026-67242","slug":"cve-2026-67242-rabbitmq-is-a-messaging-and-streaming-broker-from-4-2-0-until-4-2","title":"RabbitMQ OAuth2 token expiry bypass for fractional exp","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:12.337+00:00","url":"https://junglewise.ai/threats/cve-2026-67242-rabbitmq-is-a-messaging-and-streaming-broker-from-4-2-0-until-4-2"},{"cve":"CVE-2026-67226","slug":"cve-2026-67226-rabbitmq-is-a-messaging-and-streaming-broker-from-4-0-0-until-4-0","title":"RabbitMQ atom exhaustion in user tags management","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:11+00:00","url":"https://junglewise.ai/threats/cve-2026-67226-rabbitmq-is-a-messaging-and-streaming-broker-from-4-0-0-until-4-0"},{"cve":"CVE-2026-67225","slug":"cve-2026-67225-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3","title":"RabbitMQ stream protocol frame size validation bypass","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:10.827+00:00","url":"https://junglewise.ai/threats/cve-2026-67225-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3"},{"cve":"CVE-2026-67222","slug":"cve-2026-67222-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3","title":"RabbitMQ list_to_atom denial of service in auth_mechanism","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:10.517+00:00","url":"https://junglewise.ai/threats/cve-2026-67222-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3"},{"cve":"CVE-2026-66078","slug":"cve-2026-66078-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3","title":"RabbitMQ protected tag bypass in bulk-delete endpoint","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:10.333+00:00","url":"https://junglewise.ai/threats/cve-2026-66078-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3"},{"cve":"CVE-2026-66073","slug":"cve-2026-66073-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3","title":"RabbitMQ atom table exhaustion in management API","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:10.157+00:00","url":"https://junglewise.ai/threats/cve-2026-66073-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3"},{"cve":"CVE-2026-66071","slug":"cve-2026-66071-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3","title":"RabbitMQ atom exhaustion in OAuth2 JWT scope parsing","severity":"info","exploited":false,"published_at":"2026-09-25T17:17:09.987+00:00","url":"https://junglewise.ai/threats/cve-2026-66071-rabbitmq-is-a-messaging-and-streaming-broker-from-3-13-0-until-3"},{"cve":"CVE-2026-67236","slug":"cve-2026-67236-rabbitmq-is-a-messaging-and-streaming-broker-from-4-2-0-until-4-2","title":"RabbitMQ insecure authentication cookie in management console","severity":"info","exploited":false,"published_at":"2026-09-25T16:17:27.053+00:00","url":"https://junglewise.ai/threats/cve-2026-67236-rabbitmq-is-a-messaging-and-streaming-broker-from-4-2-0-until-4-2"},{"cve":"CVE-2026-67233","epss":0.003,"slug":"cve-2026-67233-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ authorization bypass in shovel management resource","severity":"info","exploited":false,"published_at":"2026-09-24T16:17:09.52+00:00","url":"https://junglewise.ai/threats/cve-2026-67233-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-67405","epss":0.0013,"slug":"cve-2026-67405-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ missing Origin header validation in WebSocket upgrade","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:01.663+00:00","url":"https://junglewise.ai/threats/cve-2026-67405-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-67404","epss":0.0024,"slug":"cve-2026-67404-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ OAuth2 JWKS signature verification bypass","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:01.517+00:00","url":"https://junglewise.ai/threats/cve-2026-67404-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-67235","epss":0.0026,"slug":"cve-2026-67235-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4","title":"RabbitMQ unvalidated content-header BodySize memory exhaustion","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:01.227+00:00","url":"https://junglewise.ai/threats/cve-2026-67235-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4"},{"cve":"CVE-2026-67231","epss":0.0025,"slug":"cve-2026-67231-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ trust-store plugin TLS client authentication bypass","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:00.94+00:00","url":"https://junglewise.ai/threats/cve-2026-67231-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-67229","epss":0.0028,"slug":"cve-2026-67229-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ denial of service in vhost metadata import","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:00.8+00:00","url":"https://junglewise.ai/threats/cve-2026-67229-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-67228","epss":0.0028,"slug":"cve-2026-67228-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4","title":"RabbitMQ atom table exhaustion denial of service in runtime-parameters","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:00.657+00:00","url":"https://junglewise.ai/threats/cve-2026-67228-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4"},{"cve":"CVE-2026-67219","epss":0.0026,"slug":"cve-2026-67219-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ consistent-hash exchange memory exhaustion via unbounded weight","severity":"info","exploited":false,"published_at":"2026-09-23T21:17:00.073+00:00","url":"https://junglewise.ai/threats/cve-2026-67219-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-67218","epss":0.0034,"slug":"cve-2026-67218-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4","title":"RabbitMQ privilege escalation in HTTP API super stream creation","severity":"info","exploited":false,"published_at":"2026-09-23T21:16:59.93+00:00","url":"https://junglewise.ai/threats/cve-2026-67218-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4"},{"cve":"CVE-2026-66080","epss":0.0028,"slug":"cve-2026-66080-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4","title":"RabbitMQ unbound partition count allocation in stream management","severity":"info","exploited":false,"published_at":"2026-09-23T21:16:59.787+00:00","url":"https://junglewise.ai/threats/cve-2026-66080-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-4"},{"cve":"CVE-2026-66077","epss":0.003,"slug":"cve-2026-66077-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ stored XSS in management UI connection details","severity":"info","exploited":false,"published_at":"2026-09-23T21:16:59.647+00:00","url":"https://junglewise.ai/threats/cve-2026-66077-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"},{"cve":"CVE-2026-66072","epss":0.0033,"slug":"cve-2026-66072-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3","title":"RabbitMQ stream protocol atom injection in chunk_selector","severity":"info","exploited":false,"published_at":"2026-09-23T21:16:59.213+00:00","url":"https://junglewise.ai/threats/cve-2026-66072-rabbitmq-is-a-messaging-and-streaming-broker-prior-to-versions-3"}],"vendor":{"hub":true,"name":"VMware","slug":"vmware","description":"Software company providing virtualization, cloud computing, and enterprise infrastructure solutions.","url":"https://junglewise.ai/threats/vendors/vmware"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":7},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":3,"exploited":1,"vulnerabilities":5},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-24","critical":4,"exploited":0,"vulnerabilities":37},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":27}],"most_severe":[{"cve":"CVE-2024-37079","cvss":9.8,"epss":0.8205,"slug":"cve-2024-37079-broadcom-vmware-vcenter-server-out-of-bounds-write-in-dcerpc","title":"Broadcom VMware vCenter Server out-of-bounds write in DCERPC protocol","severity":"critical","exploited":true,"published_at":"2026-01-23T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-37079-broadcom-vmware-vcenter-server-out-of-bounds-write-in-dcerpc"},{"cve":"CVE-2026-59310","cvss":9.8,"epss":0.0257,"slug":"cve-2026-59310-vmware-vcenter-directory-traversal-in-syslog-server","title":"VMware vCenter directory traversal in Syslog server","severity":"critical","exploited":true,"published_at":"2026-07-30T13:16:53.993+00:00","url":"https://junglewise.ai/threats/cve-2026-59310-vmware-vcenter-directory-traversal-in-syslog-server"},{"cve":"CVE-2024-38813","cvss":9.8,"slug":"cve-2024-38813-vmware-vcenter-server-privilege-escalation-vulnerability","title":"VMware vCenter Server Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2024-11-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38813-vmware-vcenter-server-privilege-escalation-vulnerability"},{"cve":"CVE-2024-38812","cvss":9.8,"slug":"cve-2024-38812-vmware-vcenter-server-heap-based-buffer-overflow-vulnerability","title":"VMware vCenter Server Heap-Based Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2024-11-20T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38812-vmware-vcenter-server-heap-based-buffer-overflow-vulnerability"},{"cve":"CVE-2023-34048","cvss":9.8,"slug":"cve-2023-34048-vmware-vcenter-server-out-of-bounds-write-vulnerability","title":"VMware vCenter Server Out-of-Bounds Write Vulnerability","severity":"critical","exploited":true,"published_at":"2024-01-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-34048-vmware-vcenter-server-out-of-bounds-write-vulnerability"},{"cve":"CVE-2023-20887","cvss":9.8,"slug":"cve-2023-20887-vmware-aria-operations-for-networks-command-injection","title":"Vmware Aria Operations for Networks Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-20887-vmware-aria-operations-for-networks-command-injection"},{"cve":"CVE-2022-22954","cvss":9.8,"slug":"cve-2022-22954-vmware-workspace-one-access-and-identity-manager-server-side","title":"VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2022-04-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22954-vmware-workspace-one-access-and-identity-manager-server-side"},{"cve":"CVE-2019-5544","cvss":9.8,"slug":"cve-2019-5544-vmware-esxi-and-horizon-daas-openslp-heap-based-buffer-overflow","title":"VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-5544-vmware-esxi-and-horizon-daas-openslp-heap-based-buffer-overflow"},{"cve":"CVE-2021-21972","cvss":9.8,"slug":"cve-2021-21972-vmware-vcenter-server-remote-code-execution-vulnerability","title":"VMware vCenter Server Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-21972-vmware-vcenter-server-remote-code-execution-vulnerability"},{"cve":"CVE-2021-22005","cvss":9.8,"slug":"cve-2021-22005-vmware-vcenter-server-file-upload-vulnerability","title":"VMware vCenter Server File Upload Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2021-22005-vmware-vcenter-server-file-upload-vulnerability"}],"generated_at":"2026-09-26T14:07:00.158513+00:00","technologies":[{"name":"VMware Spring Framework","slug":"spring-framework","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/spring-framework"},{"name":"VMware Cloud Foundation","slug":"cloud-foundation","vulnerabilities":21,"url":"https://junglewise.ai/threats/technologies/cloud-foundation"},{"name":"VMware Spring Security","slug":"spring-security","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/spring-security"},{"name":"VMware Spring AI","slug":"spring-ai","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/spring-ai"},{"name":"VMware ESXi","slug":"esxi","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/esxi"},{"name":"VMware Spring Boot","slug":"spring-boot","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/spring-boot"},{"name":"VMware Avi Load Balancer","slug":"avi-load-balancer","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/avi-load-balancer"},{"name":"VMware Spring for GraphQL","slug":"spring-for-graphql","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/spring-for-graphql"},{"name":"VMware Spring Integration","slug":"spring-integration","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/spring-integration"},{"name":"VMware vSphere Foundation","slug":"vsphere-foundation","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/vsphere-foundation"},{"name":"VMware Spring Web Services","slug":"web-services","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/web-services"},{"name":"VMware Fusion","slug":"fusion","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/fusion"},{"name":"VMware Spring Data REST","slug":"spring-data-rest","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/spring-data-rest"},{"name":"VMware Spring Cloud Config","slug":"spring-cloud-config","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/spring-cloud-config"},{"name":"VMware Spring Cloud Function","slug":"spring-cloud-function","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/spring-cloud-function"},{"name":"VMware Workstation","slug":"workstation","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/workstation"},{"name":"VMware Reactor Netty","slug":"reactor-netty","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/reactor-netty"},{"name":"VMware Spring AMQP","slug":"spring-amqp","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/spring-amqp"},{"name":"VMware Spring Cloud Gateway","slug":"spring-cloud-gateway","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/spring-cloud-gateway"},{"name":"VMware Cloud Foundation Operations","slug":"cloud-foundation-operations","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/cloud-foundation-operations"},{"name":"VMware Identity Manager","slug":"identity-manager","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/identity-manager"},{"name":"VMware Spring Authorization Server","slug":"spring-authorization-server","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/spring-authorization-server"},{"name":"VMware Spring Cloud Stream","slug":"spring-cloud-stream","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/spring-cloud-stream"},{"name":"VMware Spring for Apache Kafka","slug":"spring-for-apache-kafka","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/spring-for-apache-kafka"},{"name":"VMware Workspace ONE Access","slug":"workspace-one-access","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/workspace-one-access"}]}