← Vulnerability feed

Vulnerability record · CVE-2021-21985 · published 26 May 2021

CVE-2021-21985: VMware vCenter Server Virtual SAN Health Check plug-in RCE

Vmware · Vcenter Server

The vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allows an unauthenticated network attacker to execute commands with unrestricted privileges on the vCenter host operating system. Because vCenter is a high-value management plane, compromise can cascade to the whole virtual estate.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-918 · Server-side request forgery (SSRF)CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References, 2 tagged exploit
12 Aug 2026Last modified by NVD

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE in a default-enabled vCenter component, listed in KEV with known ransomware use and near-maximum EPSS.

What it is

The vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allows an unauthenticated network attacker to execute commands with unrestricted privileges on the vCenter host operating system. Because vCenter is a high-value management plane, compromise can cascade to the whole virtual estate.

Impact

An attacker gains remote code execution as the vCenter Server process, effectively full control of the underlying host OS. From there they can reach managed ESXi hosts, virtual machines and stored credentials.

Attack surface

Reachable over the network on port 443 of the vCenter Server; the CVSS vector shows no privileges required and no user interaction. The vulnerable plug-in is enabled by default, so no special configuration is needed to expose it.

Exploitation

Listed in CISA KEV with a 2021-11-03 addition and flagged for known ransomware campaign use, and EPSS 30-day probability is 0.99999. Public exploit code is referenced (Packet Storm exploit entry), so exploitation is active and widespread.

What to do

  • Apply the VMware updates in VMSA-2021-0010 to vCenter Server and Cloud Foundation immediately.
  • If patching cannot be done at once, disable the Virtual SAN Health Check plug-in per VMware guidance.
  • Restrict network access to vCenter port 443 to trusted management networks only.
  • Rotate credentials and secrets stored on or reachable from vCenter after any suspected exposure.
  • Monitor KEV due date (2021-11-17) compliance and confirm remediation in asset inventory.

Detection

  • Hunt vCenter and vpxd logs for requests to the Virtual SAN Health Check plug-in endpoints, especially unusual or malformed parameters.
  • Alert on unexpected child processes spawned by the vCenter/vpxd service, such as shells or scripting interpreters.
  • Monitor outbound connections from vCenter hosts to unfamiliar external addresses for post-exploitation activity.
  • Review authentication and access logs for anomalous access to port 443 from non-management networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-21985 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "VMware vCenter Server Improper Input Validation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21985 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2023-34048VMware vCenter Server DCERPC out-of-bounds writevCenter Server contains an out-of-bounds write in its DCERPC protocol implementation. A remote, unauthenticated attacker with network access can trig…KEVEPSS 99%analysed9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21985), CISA KEV, FIRST EPSS (scores of 2026-09-17). This page is refreshed as NVD updates the record.