Exploitation timeline
Threadlinqs has recorded 11 Vmware CVEs published between and . The busiest month was 2025-03 (3 new CVEs). 9 of them (82%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 11 of 11 tracked Vmware CVEs.
- CVE-2021-22054high 7.5KEVEPSS 93.8%
- CVE-2023-34048critical 9.8KEVEPSS 93.2%
- CVE-2024-37085medium 6.8KEVRansomwareEPSS 75.6%
- CVE-2025-22224critical 9.3KEVEPSS 50.1%
- CVE-2022-22948medium 6.5KEVEPSS 26%
- CVE-2025-22225high 8.2KEVRansomwareEPSS 8.5%
- CVE-2025-22226high 7.1KEVEPSS 3.5%
- CVE-2023-20867low 3.9KEVEPSS 2.7%
- CVE-2026-22719high 8.1KEVEPSS 2.3%
- CVE-2026-22720high 8EPSS 0.1%
- CVE-2026-22721medium 6.2EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 11 CVEs; 10 distinct Vmware products are affected. The most frequently affected:
- Cloud Foundation 8 CVEs
- Telco Cloud Infrastructure 6 CVEs
- Telco Cloud Platform 6 CVEs
- Esxi 4 CVEs
- Aria Operations 3 CVEs
- Vcenter Server 2 CVEs
- Workstation 2 CVEs
- Fusion 1 CVE
- Tools 1 CVE
- Workspace One Uem Console 1 CVE
Threat activity
30 tracked threat campaigns reference Vmware products or exploit Vmware CVEs; the 25 most recent are listed.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)HIGH
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint DefensesCRITICAL
- Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ VictimsHIGH
- Khmer Shadow: Amber Saolao cluster targets Cambodian government with NIGHTFORGE loader and Havoc DemonHIGH
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prisonHIGH
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- msaRAT: Rust-based RAT Hides C2 in Browser Process, Tied to Chaos Ransomware RaaSHIGH
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)HIGH
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeHIGH
- Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web Shell in Under 24 HoursHIGH
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework (400+ processes, 8 BYOVD variants) and 90% affiliate payoutsHIGH
- The Gentlemen RaaS (Storm-2697) — Multi-Platform Ransomware-as-a-Service with BYOVD Defense Evasion and Self-Propagating Go EncryptorHIGH
- Black Basta Ransomware Operation - Organizational Breakdown & 2025 ShutdownCRITICAL
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass ExploitationCRITICAL
- EndPoint (Midnight) Ransomware — Babuk-derived double-extortion targeting Windows, ESXi, and NASCRITICAL
- VECT 2.0 / DEVMAN 3.0 Ransomware — Design-Flawed ChaCha20 Encryption Irreversibly Destroys Files Over 128KB on Windows, Linux & ESXi (Wiper by Accident)HIGH
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)HIGH
- Pwn2Own Berlin 2026 Day Two: Microsoft Exchange RCE-as-SYSTEM Chain and 14 Other Zero-Days DisclosedHIGH
- Payouts King Ransomware — BlackBasta Successor Operation Targeting US Manufacturing, Healthcare, and Construction SectorsHIGH
- Payload Ransomware Targeting Windows and VMware ESXi with Babuk-Derived Curve25519/ChaCha20 EncryptionHIGH
- Coinbase Cartel — Data Exfiltration-Only Ransomware Group Targeting Healthcare, Tech & TransportationHIGH
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere InfrastructureCRITICAL
- UNC3886 Zero-Day Rootkit Campaign Targeting Singaporean Telecommunications — ORB Network C2, Fortinet/VMware Exploitation, Covert Infrastructure PersistenceCRITICAL
- Omnissa Workspace ONE UEM Pre-Auth SSRF Active Exploitation (CVE-2021-22054)CRITICAL
Threat actors targeting Vmware
Named threat actors attributed to campaigns that involve Vmware products or CVEs, with the number of linked campaigns:
How to prioritise Vmware patching
This order follows the data Threadlinqs holds for Vmware, not a generic severity checklist:
- 9 of 11 Vmware CVEs (82%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2021-22054, CVE-2023-34048, CVE-2024-37085.
- 2 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-22720 (0.1%), CVE-2026-22721 (0%).
- 2 CVEs score Critical and 5 High on CVSS v3 (maximum 9.8, average 7.4); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.