<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware Cloud Foundation (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/vmware-cloud-foundation.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vmware-cloud-foundation-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware Cloud Foundation (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-41252 – Description: VMware NSX contains a username enumeration vulnerability. An unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41252</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41252</strong></p>
  <p>Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts.   Impact: Username enumeration → facilitates unauthorized access.   Attack Vector: Remote, unauthenticated.   Severity: Important.   CVSSv3: 7.5 (High).   Acknowledgments: Reported by the Natio…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41251 – VMware NSX contains a weak password recovery mechanism vulnerability. An unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41251</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41251</strong></p>
  <p>VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks.  Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High).  Acknowledgments: Reported by the National Security Agency.  Af…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41231 – VMware Cloud Foundation contains a missing authorisation vulnerability. A malici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41231</guid>
    <pubDate>Tue, 20 May 2025 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41231</strong></p>
  <p>VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41230 – VMware Cloud Foundation contains an information disclosure vulnerability. A mali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41230</guid>
    <pubDate>Tue, 20 May 2025 13:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41230</strong></p>
  <p>VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41229 – VMware Cloud Foundation contains a directory traversal vulnerability. A maliciou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41229</guid>
    <pubDate>Tue, 20 May 2025 13:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41229</strong></p>
  <p>VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31678 – VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31678</guid>
    <pubDate>Fri, 28 Oct 2022 02:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31678</strong></p>
  <p>VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21972 – The vSphere Client (HTML5) contains a remote code execution vulnerability in a v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21972</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21972</strong></p>
  <p>The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Clo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21972">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
