Vmware
Vmware Telco Cloud Platform: vulnerabilidades y CVE
Vmware Telco Cloud Platform tiene 14 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses6
Críticas1
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-22719 | Alta (8.1) | 18% | ⚠ Explotación activa | 25 feb 2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations… |
| CVE-2025-41244 | Alta (7.8) | 8.4% | ⚠ Explotación activa | 29 sept 2025 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by… |
| CVE-2025-22225 | Alta (8.2) | 1.0% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. |
| CVE-2025-22224 | Alta (8.2) | 1.6% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this… |
| CVE-2025-22226 | Media (6) | 1.8% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41724 | Media (5.4) | 0.32% | — | 8 jun 2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform… |
| CVE-2026-41723 | Alta (8) | 0.42% | — | 8 jun 2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform… |
| CVE-2026-41722 | Media (5.4) | 0.32% | — | 8 jun 2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scripts to perform… |
| CVE-2026-22721 | Alta (7.2) | 0.71% | — | 25 feb 2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria… |
| CVE-2026-22720 | Crítica (9) | 0.42% | — | 25 feb 2026 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria… |
| CVE-2026-22719 | Alta (8.1) | 18% | ⚠ Explotación activa | 25 feb 2026 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations… |
| CVE-2025-41244 | Alta (7.8) | 8.4% | ⚠ Explotación activa | 29 sept 2025 | VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by… |
| CVE-2025-22245 | Media (5.9) | 0.26% | — | 4 jun 2025 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. |
| CVE-2025-22244 | Media (6.9) | 0.31% | — | 4 jun 2025 | VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation. |
| CVE-2025-22243 | Alta (7.5) | 0.34% | — | 4 jun 2025 | VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation. |
| CVE-2025-22249 | Alta (8.2) | 0.34% | — | 13 may 2025 | VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by… |
| CVE-2025-22226 | Media (6) | 1.8% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit… |
| CVE-2025-22225 | Alta (8.2) | 1.0% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. |
| CVE-2025-22224 | Alta (8.2) | 1.6% | ⚠ Explotación activa | 4 mar 2025 | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.