Cloud foundation
This hub aggregates every CVE we track for Cloud foundation. Use it to gauge the current risk picture and drill into individual advisories.
other
147
CVEs tracked
20
Critical
73
High
19
In CISA KEV
Severity distribution
HIGH73MEDIUM51CRITICAL20LOW3
Monthly trend
1
0
2
0
5
0
5
0
3
0
8
3
5
0
2
0
0
0
0
3
0
0
0
3
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Cloud foundation.
- CVE-2026-41724VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)8.0
- CVE-2026-41723VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)8.0
- CVE-2026-41722VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)8.0
- CVE-2026-22721VMware Aria Operations privilege escalation vulnerability6.2
- CVE-2026-22720VMware Aria Operations stored cross-site scripting vulnerability8.0
- CVE-2026-22719VMware Aria Operations command injection vulnerabilityKEV8.1
- CVE-2025-41250Header injection vulnerability8.5
- CVE-2025-41244VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)KEV7.8
- CVE-2025-41241Denial-of-service vulnerability4.4
- CVE-2025-41239vSockets information-disclosure vulnerability7.1
- CVE-2025-41238PVSCSI heap-overflow vulnerability9.3
- CVE-2025-41237VMCI integer-underflow vulnerability9.3
- CVE-2025-41236VMXNET3 integer-overflow vulnerability9.3
- CVE-2025-22245VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.5.9
- CVE-2025-22244VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.6.9
Product normalization is registry-driven with AI assist and human review. How it works