{"id":43109,"date":"2021-09-28T21:06:00","date_gmt":"2021-09-28T21:06:00","guid":{"rendered":"http:\/\/1548807c-2df2-4946-bd8e-c865c9045c45"},"modified":"2021-09-28T21:06:00","modified_gmt":"2021-09-28T21:06:00","slug":"exploit-released-for-vmware-vulnerability-after-cisa-warning","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","title":{"rendered":"Exploit released for VMware vulnerability after CISA warning"},"content":{"rendered":"<p>A working exploit for CVE-2021-22005 &#8212; a vulnerability with VMware vCenter &#8212; has been released and is reportedly being used by threat actors, according to experts tracking the issue.&nbsp;<\/p>\n<p>Last week, VMware <a href=\"https:\/\/www.zdnet.com\/article\/rce-is-back-vmware-details-file-upload-vulnerability-in-vcenter-server\/\">warned of a critical vulnerability<\/a> in the analytics service of vCenter Server and urged users to update their systems as soon as possible.&nbsp;<\/p>\n<p>On September 21, <a href=\"https:\/\/core.vmware.com\/vmsa-2021-0020-questions-answers-faq\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">VMware said<\/a> that its vCenter Server is affected by an arbitrary file upload vulnerability in the Analytics service which would allow a malicious actor with network access to exploit this vulnerability to execute code on vCenter Servers.&nbsp;<\/p>\n<p>By September 24, VMware had confirmed reports that CVE-2021-22005 was being exploited in the wild and dozens of security researchers online <a href=\"https:\/\/twitter.com\/bad_packets\/status\/1440893196993634307\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">reported mass scanning<\/a> for vulnerable vCenter Servers and publicly available exploit codes.&nbsp;<\/p>\n<p>CISA <a href=\"https:\/\/us-cert.cisa.gov\/ncas\/current-activity\/2021\/09\/24\/vmware-vcenter-server-vulnerability-cve-2021-22005-under-active\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">followed up<\/a> with its own warning on Friday, writing on Twitter that they expected &#8220;widespread exploitation of VMware vCenter Server CVE-2021-22005.&#8221; Like VMware, they urged users to upgrade to a fixed version as quickly as possible or apply the temporary workaround provided by VMware.&nbsp;<\/p>\n<p>That same day, cybersecurity company Censys <a href=\"https:\/\/censys.io\/blog\/vmware-cve-2021-22005-technical-impact-analysis\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">released a report<\/a> showing that there were around 3,264 hosts that are Internet-facing and potentially vulnerable. More than 430 had been patched and 1,369 are either unaffected versions or have the workaround applied.<\/p>\n<p>In a statement to ZDNet, VMware reiterated that it has <a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0020.html\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">released patches and mitigation guidance<\/a> to address multiple vulnerabilities affecting VMware vCenter Server 6.5, 6.7 and 7.0. They have also issued a public security advisory.&nbsp;<\/p>\n<section class=\"sharethrough-top placeholder\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>&#8220;Customer protection is VMware&#8217;s top priority, and we strongly recommend that affected customers patch immediately as indicated in the advisory. As a matter of best practice, VMware encourages all customers to apply the latest product updates, security patches and mitigations made available for their specific environment and deploy our products in a security hardened configuration,&#8221; the company said.&nbsp;<\/p>\n<p>&#8220;Customers should also sign-up for VMware&#8217;s Security-Announce mailing list to receive new and updated VMware Security Advisories.&#8221;<\/p>\n<p>Derek Abdine, CTO of Censys, confirmed to ZDNet that they have reliably proven that remote execution is possible and easy to do.&nbsp;<\/p>\n<p>&#8220;I can confirm in-the-wild exploitation now. It looks like it&#8217;s related to the second vulnerability that is part of CVE-2021-22005. I haven&#8217;t seen evidence of exploitation using the hyper\/send endpoint (the other part of CVE-2021-22005), but that endpoint is slightly less viable because it has a prerequisite condition. The \/datapp endpoint is more concerning as there are no prerequisites and it is thought to exist on more versions of vCenter,&#8221; Abdine explained.&nbsp;<\/p>\n<p>&#8220;Also, internal exposure is still a big deal. There are quite a number of these externally facing, but that should not be the norm. Many organizations have private VMware clusters, and this issue will still present a significant risk to them if an attacker is able to leverage the exploit internally.&#8221;<\/p>\n<p>Will Dormann, vulnerability analyst at the CERT\/CC, <a href=\"https:\/\/twitter.com\/wdormann\/status\/1442674943494397956\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">also confirmed on Twitter<\/a> that the exploit for CVE-2021-22005 is now fully public.&nbsp;<\/p>\n<figure class=\"image image-large shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/\" class=\"lazy\" alt=\"censys-vmware-1.png\" height=\"auto\" width=\"470\" data-original=\"https:\/\/www.zdnet.com\/a\/img\/resize\/84703beea4c6dd64ccafa9c536beb6b36cc8d84e\/2021\/09\/28\/52106328-cb70-4953-a425-e30ec3169289\/censys-vmware-1.png?width=470&amp;fit=bounds&amp;auto=webp\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/84703beea4c6dd64ccafa9c536beb6b36cc8d84e\/2021\/09\/28\/52106328-cb70-4953-a425-e30ec3169289\/censys-vmware-1.png?width=470&amp;fit=bounds&amp;auto=webp\" class alt=\"censys-vmware-1.png\" height=\"auto\" width=\"470\"><\/span><\/noscript><figcaption readability=\"1\"><span class=\"caption\" readability=\"2\"><\/p>\n<p>A map of where all VMware vCenter hosts accessible via the Internet are located.&nbsp;<\/p>\n<p><\/span><span class=\"credit\"> Censys <\/span><\/figcaption><\/figure>\n<p>Hosts from Hong Kong, Vietnam, the Netherlands, Japan, Singapore and other countries <a href=\"https:\/\/twitter.com\/bad_packets\/status\/1442950518754537472\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">across the globe<\/a> continue to scan for the vulnerability, according to Bad Packets.<\/p>\n<p>Abdine noted that while a patch has been available for days, there is a &#8220;patch saturation&#8221; phenomenon where patching never really reaches 100%.&nbsp;<\/p>\n<p>&#8220;For example, 5 days after the <a href=\"https:\/\/www.zdnet.com\/article\/us-cybercom-says-mass-exploitation-of-atlassian-confluence-vulnerability-ongoing-and-expected-to-accelerate\/\" target=\"_blank\" rel=\"noopener\">Atlassian Confluence<\/a> blog post went out, we only saw a drop of 30% on total exposed vulnerable confluence services. When the Western Digital My Book Live issue came up recently, we observed the same thing even in the consumer space (versus enterprise software for Confluence\/VMware),&#8221; Abdine said.<\/p>\n<p>&#8220;I think there are still plenty of hosts out there that are a concern. Greynoise.io and Bad Packets are both seeing opportunistic scanning that some are calling mass exploitation. However, from what I can tell so far, whoever is running these requests that are captured by Greynoise and Bad Packets are simply lifting URLs from community research (by Censys and @testanull on Twitter) and attempting to hit the URLs for those without full working knowledge of how to achieve execution.&#8221;&nbsp;<\/p>\n<p>Now that an exploit has been released, Abdine added that the &#8220;floodgates opened,&#8221; allowing any attacker with lower technical skills to perform mass exploitation.<\/p>\n<p>&#8220;So all in all, I don&#8217;t think we&#8217;re out of the woods yet &#8212; and again, it&#8217;s very common to run VMware clusters in internal datacenters that are only accessible via company VPNs. Virtual machines should continue to run. However, the operations and management you get with vCenter will absolutely be affected while the upgrade takes place, and may likely impact operations for organizations regularly using vCenter,&#8221; Abdine said.&nbsp;<\/p>\n<p>John Bambenek, principal threat hunter at Netenrich, told ZDNet that remote code execution as root on these types of devices is pretty significant.&nbsp;<\/p>\n<p>Almost every organization operates virtual machines and if a threat actor has root access, they could ransom every machine in that environment or steal the data on those virtual machines with relative ease, Bambenek said.&nbsp;<\/p>\n<p>Other experts, like Digital Shadows threat intelligence team lead Alec Alvarado, noted that threat actors follow the news as much as security researchers. Alvarado echoed what Abdine said, explaining that less sophisticated actors now have a chance to take advantage of the vulnerability thanks to the proof of concept.&nbsp;<\/p>\n<p>But for Bud Broomhead, CEO at Viakoo, the situation boiled down to patch management.&nbsp;<\/p>\n<p>&#8220;Managing patches manually leaves an organization at risk due to the slow (or non-existent) nature of the process, leaving an organization vulnerable,&#8221; Broomhead said.&nbsp;<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VMware, CISA and many experts have been begging people to address the CVE-2021-22005 issue.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-43109","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Exploit released for VMware vulnerability after CISA warning 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Exploit released for VMware vulnerability after CISA warning 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-28T21:06:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Exploit released for VMware vulnerability after CISA warning\",\"datePublished\":\"2021-09-28T21:06:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\"},\"wordCount\":957,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\",\"name\":\"Exploit released for VMware vulnerability after CISA warning 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\",\"datePublished\":\"2021-09-28T21:06:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/exploit-released-for-vmware-vulnerability-after-cisa-warning\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Exploit released for VMware vulnerability after CISA warning\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Exploit released for VMware vulnerability after CISA warning 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","og_locale":"en_US","og_type":"article","og_title":"Exploit released for VMware vulnerability after CISA warning 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-09-28T21:06:00+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Exploit released for VMware vulnerability after CISA warning","datePublished":"2021-09-28T21:06:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/"},"wordCount":957,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","url":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","name":"Exploit released for VMware vulnerability after CISA warning 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","datePublished":"2021-09-28T21:06:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#primaryimage","url":"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/","contentUrl":"https:\/\/www.zdnet.com\/article\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/exploit-released-for-vmware-vulnerability-after-cisa-warning\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Exploit released for VMware vulnerability after CISA warning"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=43109"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43109\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=43109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=43109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=43109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}