CVE-2021-21985
CVE-2021-21985 is a critical-severity vulnerability in Vmware Vcenter Server with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2021-11-03). The underlying weakness is classified as CWE-918.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 10.0
- EPSS exploit prediction: 100% (100th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2021-11-03)
- EU (EUVD) id: EUVD-2021-9156
- EU exploitation: Flagged exploited in the ENISA EU Vulnerability Database (since 2021-11-03)
- Weakness: CWE-918
- Affected product: Vmware Vcenter Server
- Published:
- Last modified:
Description
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Frequently asked questions
- What is CVE-2021-21985?
- The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
- How severe is CVE-2021-21985?
- CVE-2021-21985 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2021-21985 being actively exploited?
- Yes. CVE-2021-21985 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2021-11-03, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2021-21985?
- CVE-2021-21985 primarily affects Vmware Vcenter Server. In total, 52 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2021-21985?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- Does CVE-2021-21985 have an EU (EUVD) identifier?
- Yes. CVE-2021-21985 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2021-9156. It is also flagged as exploited in the EUVD (since 2021-11-03).
- When was CVE-2021-21985 published?
- CVE-2021-21985 was published on 2021-05-26 and last updated on 2026-08-12.
References
- http://packetstormsecurity.com/files/162812/VMware-Security-Advisory-2021-0010.html
- http://packetstormsecurity.com/files/163487/VMware-vCenter-Server-Virtual-SAN-Health-Check-Remote-Code-Execution.html
- https://www.vmware.com/security/advisories/VMSA-2021-0010.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21985
Affected products (52)
- cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update1:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update1b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update1c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.5:update3n:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3l:*:*:*:*:*:*
- cpe:2.3:a:vmware:vcenter_server:6.7:update3m:*:*:*:*:*:*
More vulnerabilities in Vmware Vcenter Server
- CVE-2015-2342 — Critical (CVSS 10.0): The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not…
- CVE-2013-1405 — Critical (CVSS 10.0): VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client…
- CVE-2026-59310 — Critical (CVSS 9.8): VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network…
- CVE-2024-38812 — Critical (CVSS 9.8): The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious…
- CVE-2024-37080 — Critical (CVSS 9.8): vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor…
- CVE-2024-37079 — Critical (CVSS 9.8): vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor…
All CVEs affecting Vmware Vcenter Server →
Other CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities
- CVE-2026-69502 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-65801 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges…
- CVE-2026-48331 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in…
- CVE-2026-54735 — Critical (CVSS 10.0): Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version…
- CVE-2026-57106 — Critical (CVSS 10.0): Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-15409 — Critical (CVSS 10.0): A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A…
Browse all CWE-918 (Server-Side Request Forgery (SSRF)) vulnerabilities →