<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://exploit-radar.com/en/flux/categories/virtualisation.xml</id>
  <title>Exploit Radar: Virtualization, VDI and cloud</title>
  <subtitle>The latest additions to CISA’s catalog of exploited vulnerabilities in the “Virtualization, VDI and cloud” category (indicative classification).</subtitle>
  <link rel="self" type="application/atom+xml" href="https://exploit-radar.com/en/flux/categories/virtualisation.xml"/>
  <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/produits/virtualisation/"/>
  <updated>2026-08-18T00:00:00Z</updated>
  <author><name>Exploit Radar</name></author>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2026-59310/</id>
    <title>CVE-2026-59310 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2026-59310/"/>
    <updated>2026-08-18T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. Start with internet-facing devices. CISA also asks you to hunt for signs of compromise: patching is not enough if the device has already been breached. CISA deadline: 3 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on August 18, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-37079/</id>
    <title>CVE-2024-37079 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-37079/"/>
    <updated>2026-01-23T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. For cloud services, follow the guidance from VMware (Broadcom). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on January 23, 2026.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-41244/</id>
    <title>CVE-2025-41244 — VMware (Broadcom) VMware Tools</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-41244/"/>
    <updated>2025-10-30T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. For cloud services, follow the guidance from VMware (Broadcom). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on October 30, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-8068/</id>
    <title>CVE-2024-8068 — Citrix Session Recording</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-8068/"/>
    <updated>2025-08-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. For cloud services, follow the guidance from Citrix. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 25, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-8069/</id>
    <title>CVE-2024-8069 — Citrix Session Recording</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-8069/"/>
    <updated>2025-08-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Citrix; if none are available, stop using the product. For cloud services, follow the guidance from Citrix. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on August 25, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-22224/</id>
    <title>CVE-2025-22224 — VMware (Broadcom) ESXi</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-22224/"/>
    <updated>2025-03-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. For cloud services, follow the guidance from VMware (Broadcom). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 4, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-22225/</id>
    <title>CVE-2025-22225 — VMware (Broadcom) ESXi</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-22225/"/>
    <updated>2025-03-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. For cloud services, follow the guidance from VMware (Broadcom). CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on March 4, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-22226/</id>
    <title>CVE-2025-22226 — VMware (Broadcom) ESXi</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-22226/"/>
    <updated>2025-03-04T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. For cloud services, follow the guidance from VMware (Broadcom). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 4, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-49035/</id>
    <title>CVE-2024-49035 — Microsoft Partner Center</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-49035/"/>
    <updated>2025-02-25T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. For cloud services, follow the guidance from Microsoft. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 25, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2025-24989/</id>
    <title>CVE-2025-24989 — Microsoft Power Pages</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2025-24989/"/>
    <updated>2025-02-21T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from Microsoft; if none are available, stop using the product. For cloud services, follow the guidance from Microsoft. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on February 21, 2025.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-38812/</id>
    <title>CVE-2024-38812 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-38812/"/>
    <updated>2024-11-20T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 20, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-38813/</id>
    <title>CVE-2024-38813 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-38813/"/>
    <updated>2024-11-20T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on November 20, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2024-37085/</id>
    <title>CVE-2024-37085 — VMware (Broadcom) ESXi</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2024-37085/"/>
    <updated>2024-07-30T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. CISA deadline: 21 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on July 30, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2022-22948/</id>
    <title>CVE-2022-22948 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2022-22948/"/>
    <updated>2024-07-17T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on July 17, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-34048/</id>
    <title>CVE-2023-34048 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-34048/"/>
    <updated>2024-01-22T00:00:00Z</updated>
    <summary type="text">Apply the patches or mitigations from VMware (Broadcom); if none are available, stop using the product. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on January 22, 2024.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2023-20867/</id>
    <title>CVE-2023-20867 — VMware (Broadcom) VMware Tools</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2023-20867/"/>
    <updated>2023-06-23T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on June 23, 2023.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-21973/</id>
    <title>CVE-2021-21973 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-21973/"/>
    <updated>2022-03-07T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on March 7, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2008-3431/</id>
    <title>CVE-2008-3431 — Oracle VirtualBox</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2008-3431/"/>
    <updated>2022-03-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Oracle. CISA deadline: 21 days. Added to CISA’s catalog of exploited vulnerabilities on March 3, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22017/</id>
    <title>CVE-2021-22017 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22017/"/>
    <updated>2022-01-10T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on January 10, 2022.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-11634/</id>
    <title>CVE-2019-11634 — Citrix Workspace app / Receiver</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-11634/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Citrix. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-5544/</id>
    <title>CVE-2019-5544 — VMware (Broadcom) ESXi</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-5544/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-3952/</id>
    <title>CVE-2020-3952 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-3952/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-3992/</id>
    <title>CVE-2020-3992 — VMware (Broadcom) ESXi</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-3992/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-1497/</id>
    <title>CVE-2021-1497 — Cisco HyperFlex HX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-1497/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Cisco. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-1498/</id>
    <title>CVE-2021-1498 — Cisco HyperFlex HX</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-1498/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Cisco. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-21972/</id>
    <title>CVE-2021-21972 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-21972/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-21985/</id>
    <title>CVE-2021-21985 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-21985/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-22005/</id>
    <title>CVE-2021-22005 — VMware (Broadcom) vCenter Server</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-22005/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-38647/</id>
    <title>CVE-2021-38647 — Microsoft Open Management Infrastructure (OMI)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-38647/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 14 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-1040/</id>
    <title>CVE-2020-1040 — Microsoft Hyper-V</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-1040/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2020-3950/</id>
    <title>CVE-2020-3950 — VMware (Broadcom) Workstation / Fusion</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2020-3950/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from VMware (Broadcom). CISA deadline: 181 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-38645/</id>
    <title>CVE-2021-38645 — Microsoft Open Management Infrastructure (OMI)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-38645/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-38648/</id>
    <title>CVE-2021-38648 — Microsoft Open Management Infrastructure (OMI)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-38648/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2021-38649/</id>
    <title>CVE-2021-38649 — Microsoft Open Management Infrastructure (OMI)</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2021-38649/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Microsoft. CISA deadline: 14 days. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
  <entry>
    <id>https://exploit-radar.com/en/cve/CVE-2019-13608/</id>
    <title>CVE-2019-13608 — Citrix StoreFront</title>
    <link rel="alternate" type="text/html" href="https://exploit-radar.com/en/cve/CVE-2019-13608/"/>
    <updated>2021-11-03T00:00:00Z</updated>
    <summary type="text">Apply the security update from Citrix. CISA deadline: 181 days. Used in ransomware campaigns. Added to CISA’s catalog of exploited vulnerabilities on November 3, 2021.</summary>
  </entry>
</feed>
