VMware's VMSA-2021-0020 security advisory addresses multiple vulnerabilities in vCenter Server and Cloud Foundation, including CVE-2021-22005, a critical remotely exploitable file-upload flaw rated CVSS 9.8. An attacker with network access to vCenter can exploit the issue regardless of vCenter configuration and execute commands or deploy software on the vCenter Server Appliance; public working exploits became available shortly after disclosure.
Organizations should apply VMware's updates immediately and treat exposed or unpatched vCenter infrastructure as potentially compromised. Patching removes the vulnerable condition but does not reveal prior exploitation, so incident-response teams should conduct compromise assessments and threat hunting, while retaining sufficient forensic telemetry to investigate potential ransomware activity or other follow-on intrusion.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Working public exploits for the disclosed VMware vulnerabilities became available quickly, increasing the risk to organizations with unpatched vCenter Server and Cloud Foundation deployments.
VMware disclosed CVE-2021-22005, a CVSS 9.8 remotely exploitable file-upload vulnerability that can allow command or software execution on the vCenter Server Appliance, along with 18 additional vCenter Server 7.0 vulnerabilities. The affected flaws also impact VMware Cloud Foundation 4.x; fixed versions and some workarounds were made available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
mitiga.io
Open sourceblogs.vmware.com
Open sourcevmware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.