Skip to content
Signals
Monitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real timeMonitoring NVD, CISA KEV, EPSS and the Dragons Community ransomware tracker in near-real time

Vendors · vmware

vmware

· 86 Critical

Total CVEs

986

Critical

86

Products

195

Search All CVEs →

986

Products (195)

workstation217 CVEsesxi139 CVEscloud foundation133 CVEsfusion131 CVEsplayer89 CVEsesx86 CVEsvcenter server79 CVEsvsphere61 CVEsserver59 CVEsspring framework56 CVEsace44 CVEsspring security32 CVEsidentity manager28 CVEsworkstation pro27 CVEsworkstation player26 CVEshorizon client25 CVEstools22 CVEsvrealize suite lifecycle manager21 CVEsvrealize automation20 CVEsspring boot19 CVEsvrealize operations18 CVEsvmware workstation15 CVEsworkspace one access15 CVEsvrealize log insight15 CVEsvcenter server appliance14 CVEshorizon view14 CVEsspring ai14 CVEsaria operations13 CVEsidentity manager connector13 CVEstelco cloud platform11 CVEsone access11 CVEsvirtualcenter10 CVEstelco cloud infrastructure10 CVEsvmware server9 CVEsaccess connector9 CVEsvsphere data protection8 CVEsvrealize operations manager8 CVEsaria operations for logs8 CVEsspring cloud config8 CVEsesx server8 CVEsaria operations for networks8 CVEsvma7 CVEsview7 CVEssd-wan orchestrator6 CVEshorizon view client6 CVEsremote console6 CVEshorizon6 CVEsmovie decoder6 CVEsgsx server6 CVEsrabbitmq6 CVEsphoton os6 CVEsopen vm tools5 CVEsvcloud director5 CVEsvmware player5 CVEsvcenter5 CVEsfusion pro5 CVEsworkspace one assist5 CVEsspring for graphql4 CVEscarbon black app control4 CVEshorizon daas4 CVEsairwatch4 CVEsspringsource spring security4 CVEsvsphere client4 CVEsspring advanced message queuing protocol4 CVEsinstallbuilder3 CVEsixgben3 CVEsairwatch agent3 CVEscloud director3 CVEsvrealize network insight3 CVEsvrealize orchestrator3 CVEssingle sign-on for pivotal cloud foundry3 CVEsspring cloud gateway3 CVEsspring hateoas3 CVEsspring integration zip3 CVEsaria automation3 CVEsstudio3 CVEspinniped2 CVEsairwatch inbox2 CVEsopen-vm-tools2 CVEsvmware player 22 CVEsaccess2 CVEsvmware hcx2 CVEsvmware esxi2 CVEsvmware esx2 CVEsvm-support2 CVEsgemfire2 CVEsspring cloud data flow2 CVEsspring cloud function2 CVEstc server2 CVEsspring cloud netflix2 CVEsapp volumes2 CVEsvix api2 CVEsapplication remote collector2 CVEsvirtual infrastructure client2 CVEsnsx edge2 CVEsnsx data center2 CVEsspring data rest2 CVEsairwatch console2 CVEsvelocloud orchestrator2 CVEsace 22 CVEsspring grpc2 CVEshyperic hq2 CVEsspring integration2 CVEshyperic server2 CVEstanzu gemfire for virtual machines2 CVEstanzu application service for virtual machines2 CVEsvcenter orchestrator2 CVEsinfrastructure2 CVEsrabbitmq java client2 CVEsworkspace one content2 CVEsworkspace one boxer2 CVEsworkspace one uem console2 CVEsvcenter chargeback manager2 CVEsvsphere esxi2 CVEszimbra desktop1 CVEsairwatch launcher1 CVEsams1 CVEsbosh editor1 CVEscapacityiq1 CVEscarbon black cloud1 CVEscarbon black cloud workload1 CVEscloud foundation operations1 CVEscloudfoundry manifest yml support1 CVEsconcourse ci pipeline editor1 CVEsgreenplum database1 CVEsharbor container registry1 CVEshorizon view agent1 CVEshorizon view agents1 CVEshyperic agent1 CVEsi40en1 CVEsintelligent hub1 CVEsisolation segment1 CVEslab manager1 CVEsnsx1 CVEsnsx-v edge1 CVEsnsx sd-wan by velocloud1 CVEsoperations manager1 CVEsovf tool1 CVEspivotal scheduler1 CVEspivotal software mysql1 CVEssd-wan by velocloud1 CVEssd-wan edge1 CVEssd-wan edge firmware1 CVEssingle sign-on for tanzu1 CVEsspring boot tools1 CVEsspring cloud contract1 CVEsspring cloud netflix zuul1 CVEsspring cloud openfeign1 CVEsspring cloud sso connector1 CVEsspring cloud task1 CVEsspring cloud vault1 CVEsspring data mongodb1 CVEsspring for apache kafka1 CVEsspring session1 CVEsspring social1 CVEsspring tools1 CVEsspring vault1 CVEsstage manager1 CVEstanzu application service for vms1 CVEsthinapp1 CVEsunified access gateway1 CVEsvcenter lab manager1 CVEsvcenter operations1 CVEsvcenter stage manager1 CVEsvcenter update manager1 CVEsvcloud automation center1 CVEsvcloud automation identity appliance1 CVEsvcloud networking and security1 CVEsvcloud networking and security edge1 CVEsvelero1 CVEsvi-client1 CVEsview manager1 CVEsview planner1 CVEsvmware ace1 CVEsvmware virtualcenter1 CVEsvrealize business advanced and enterprise1 CVEsvrealize business for cloud1 CVEsvrealize operations for horizon1 CVEsvrealize operations for published applications1 CVEsvrealize operations tenant1 CVEsvshield manager1 CVEsvsphere integrated containers1 CVEsvsphere replication1 CVEsworkspace one1 CVEsworkspace one intelligent hub1 CVEsworkspace one launcher1 CVEsworkspace one notebook1 CVEsworkspace one people1 CVEsworkspace one piv-d manager1 CVEsworkspace one sdk1 CVEsworkspace one sdk \(objective-c\)1 CVEsworkspace one uem1 CVEsworkspace one unified endpoint management1 CVEsworkspace one web1 CVEsxenon1 CVEs

Recent Vulnerabilities

View all 986
CVE-2026-41856HIGH 7.5

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

CVE-2026-41700HIGH 8.1

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

CVE-2026-41699HIGH 8.1

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.

CVE-2026-41694LOW 3.7

Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41003HIGH 7.6

An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-40988HIGH 7.5

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

CVE-2026-41852LOW 3.7

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41848LOW 3.7

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41847MEDIUM 4.8

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVE-2026-41846MEDIUM 5.9

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41845HIGH 7.1

Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41844MEDIUM 4.2

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41838MEDIUM 4.8

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVE-2026-41007HIGH 7.5

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

CVE-2026-41006HIGH 7.5

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

CVE-2026-41702HIGH 7.8

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

CVE-2026-41713HIGH 8.2

A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.

CVE-2026-41712HIGH 7.5

Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.

CVE-2026-41705HIGH 8.6

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgrade to 1.0.7 or greater. Spring AI 1.1.x: affected from 1.1.0 through latest 1.1.x; upgrade to 1.1.6 or greater.

CVE-2026-41004MEDIUM 4.4

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-41002HIGH 7.2

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-40982CRITICAL 9.1

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-40981HIGH 7.5

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVE-2026-22745MEDIUM 5.3

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application.

CVE-2026-22741LOW 3.1

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title  with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients.