VendorsVMwaretelco_cloud_infrastructureall versions
Vulnerabilities

VMware Telco Cloud Infrastructure (TCI)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-59310
vCenter directory-traversal vulnerability
Published 2026-07-30 · Analyzed
9.8KEVEPSS 0.026
CVE-2026-59309
vCenter authentication-bypass vulnerability
Published 2026-07-30 · Analyzed
9.8EPSS 0.006
CVE-2025-22224
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Published 2025-03-04 · Analyzed
9.3KEVEPSS 0.016
CVE-2026-22720
VMware Aria Operations stored cross-site scripting vulnerability
Published 2026-02-25 · Analyzed
9.0EPSS 0.004
CVE-2025-22225
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox.
Published 2025-03-04 · Analyzed
8.2KEVEPSS 0.010
CVE-2026-22719
VMware Aria Operations command injection vulnerability
Published 2026-02-25 · Analyzed
8.1KEVEPSS 0.177
CVE-2025-41244
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
Published 2025-09-29 · Analyzed
7.8KEVEPSS 0.084
CVE-2025-22243
VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.
Published 2025-06-04 · Analyzed
7.5EPSS 0.003
CVE-2026-22721
VMware Aria Operations privilege escalation vulnerability
Published 2026-02-25 · Analyzed
7.2EPSS 0.007
CVE-2025-22226
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Published 2025-03-04 · Analyzed
7.1KEVEPSS 0.017
CVE-2025-22244
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
Published 2025-06-04 · Analyzed
6.9EPSS 0.003
CVE-2025-22245
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.
Published 2025-06-04 · Analyzed
5.9EPSS 0.003