LIVE · cybersecurity feed
Live wire
vendor1 exploited in the wild

Vmware

57 CVEs published in the last four months and 7 stories. Exploited flaws first.

Critical10
High45
Medium1
Exploited (KEV)1

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-59310exploited9.8criticalvcenter serverVMware vCenter contains a directory traversal vulnerability in the Syslog server.37d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-59310exploited9.8criticalvcenter serverVMware vCenter contains a directory traversal vulnerability in the Syslog server.37d ago
CVE-2026-593099.8criticalvcenter serverVMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.37d ago
CVE-2026-593139.8criticalspring frameworkSpring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-S9d ago
CVE-2026-478929.8criticalspring frameworkA WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header9d ago
CVE-2026-478919.8criticalspring frameworkA Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce 9d ago
CVE-2026-478909.8criticalspring frameworkSpring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with v9d ago
CVE-2026-593549.6criticalspring securityIn versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Regis9d ago
CVE-2026-592709.4criticalspring securitySpring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative 9d ago
CVE-2026-592839.1criticalspring frameworkApplications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vuln9d ago
CVE-2026-227329.1criticalspring securityWhen applications specify HTTP response headers for servlet applications using Spring Security, there is the possi170d ago
CVE-2026-227308.8highspring aiA critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass 171d ago
CVE-2026-478358.6highspring aiIn Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasti82d ago
CVE-2026-227298.6highspring aiA JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to 171d ago
CVE-2026-227398.6highspring cloud configVulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Conf166d ago
CVE-2026-417138.2highspring aiA malicious user could craft input that is stored in conversation memory and later interpreted by the model in an 116d ago
CVE-2026-227318.2highspring bootSpring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an appli170d ago
CVE-2026-227338.2highspring bootSpring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an appli170d ago
CVE-2026-478778.2highspring securitySpring Security Authorization Server's default consent page renders user-controlled values without HTML entity enc9d ago
CVE-2026-593248.2highspring integrationWhen an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads9d ago
CVE-2026-417328.1highspring for apache pulsarJsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting a88d ago
CVE-2026-592868.1highspring for graphqlThe GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresourc9d ago
CVE-2026-416998.1highspring for graphqlSpring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries86d ago
CVE-2026-417008.1highspring for graphqlSpring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket H86d ago
CVE-2026-417298.1highspring data restSpring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patc88d ago
CVE-2026-417318.1highspring for apache kafkaJsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages us88d ago
CVE-2026-418558.1highspring frameworkIn an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org88d ago
CVE-2026-417178.1highspring data mongodbSpring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability.88d ago
CVE-2026-592858.1highspring for graphqlSpring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries9d ago
CVE-2026-417238higharia operationsVMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor89d ago
CVE-2026-417228higharia operationsVMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor89d ago
CVE-2026-417248higharia operationsVMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor89d ago
CVE-2026-593078highspring integrationAn operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection 9d ago
CVE-2026-417027.8highfusionVMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performe113d ago
CVE-2026-410037.6highspring securityAn attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms g88d ago
CVE-2026-418497.5highspring frameworkAn integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL).88d ago
CVE-2026-409887.5highspring securityAn application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout 88d ago
CVE-2026-417287.5highspring data restSpring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter 88d ago
CVE-2026-418567.5highspring for graphqlThe Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotati86d ago
CVE-2026-418427.5highspring frameworkSpring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resour88d ago
CVE-2026-410077.5highspring hateoasSpring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied stri88d ago
CVE-2026-410067.5highspring hateoasSpring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER me88d ago
CVE-2026-478527.5highspring aiA local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model10d ago
CVE-2026-478517.5highspring aiAnalyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion t10d ago
CVE-2026-478937.5highspring frameworkA Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information 9d ago
CVE-2026-417127.5highspring aiSpring AI's chat memory component contained a problematic default that, when not explicitly overridden, could resu116d ago
CVE-2026-592827.5highspring frameworkSpring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths 9d ago
CVE-2026-592897.5highspring for graphqlSpring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the clie9d ago
CVE-2026-418507.5highspring frameworkApplications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algori88d ago
CVE-2026-478417.4highspring securityAn application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a10d ago
CVE-2026-592887.4highspring for graphqlThe GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application.9d ago
CVE-2026-409937.3highspring securityAn attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_as88d ago
CVE-2026-478367.2highspring cloud configThe base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN re10d ago
CVE-2026-418457.1highspring frameworkDue to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in 88d ago
CVE-2026-409877.1highspring integrationA malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outsid86d ago
CVE-2026-478497.1highspring data restSpring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 J9d ago
CVE-2026-227375.9mediumspring frameworkUse of Java scripting engine enabled (e.g.170d ago
CVE-2026-227352.6lowspring frameworkSpring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE).170d ago

Filter the full tracker by Vmware

Our coverage of Vmware

CVE-2026-59346critical

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

vulnerabilitycritical

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

vulnerability

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek.

CVE-2026-33824

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-33824 is a Windows Internet Key Exchan

CVE-2026-59310critical

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

vulnerabilitycritical

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

vmwarehigh

CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX

CrowdStrike researchers have identified 21 novel methods for obfuscating shell commands on VMware ESX hypervisors. These techniques, ranging from simple encoding to complex cryptographic ciphers and invisible Unicode characters, evade traditional log-based detection by exploiting the parsing stage of command execution. CrowdStrike has developed detection patterns to identify these obfuscated commands at scale, enhancing security for ESX environments frequently targeted by ransomware.