CVE-2021-21972Disclosure(vmware / cloud_foundation)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for vmware cloud_foundation systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • vcenter_server

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
cloud_foundationvcenter_server

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-04: 2PoC Mentioned / Linked · 2026-08-04: 1Exploit Tool / Code · 2026-08-04: 108-04
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-gXcrY61 ( CVE-2021-44228 ) EGE-GH-mlHKBE9 ( CVE-2021-44228 ) EGE-GH-UkC3bPM ( CVE-2026-57827 ) EGE-GH-kQvdrdy ( CVE-2021-21972 ) EGE-GH-UzPcxEL ( CVE-2023-33246 ) ..🧵👇

    Post summary

    The tweet announces a list of several CVEs as critically disclosed exploits, providing no detailed information or evidence of exploitation.

    1101043
    29 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-kQvdrdy [CRITICAL/PoC] Linked: CVE-2021-21972 CVE-2021-21972 🔗 https://exploitgrid.net/exploits/517e3dbc-4e92-4c64-9862-1c2d3b6362b7

    Post summary

    The post advertises a PoC for CVE‑2021‑21972 via a link to ExploitGrid, but does not provide detailed exploit instructions, patch information, or evidence of active exploitation.

    1000023
    29 followersView on X
CPE platform detail42 entries

42 of 42 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.5--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server6.7--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--

Explore more