CVE-2021-21972CISA KEVEPSS p99.9%

CVE-2021-21972VMware vCenter Server Remote Code Execution Vulnerability

VMware / vCenter Server

Description

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.

Scoring

EPSS99.57% probability of exploitation · percentile 99.9% · 2026-06-15T12:03:41Z

CISA KEV entry

Added to KEV: 2021-11-03

(incoming)1

TypeTargetConfidenceTier
KEVEntryVMware vCenter Server Remote Code Execution Vulnerabilitykev-cve-2021-219720%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
VMware vCenter Server Improper Input Validation Vulnerability
CVE
VMware vCenter Server File Upload Vulnerability
CVE
VMware vCenter Server Incorrect Default File Permissions Vulnerability
CVE
VMware vCenter Server Out-of-Bounds Write Vulnerability
CVE
VMware vCenter Server Heap-Based Buffer Overflow Vulnerability
CVE
VMware vCenter Server Improper Access Control
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.