critical Known exploitedREV. 01

CVE-2021-21985VMware vCenter Server — vSphere Client Plug-in Remote Code Execution

A plug-in that ships enabled in VMware vCenter Server — the storage health check in the vSphere web client — never validates its input, so anyone who can reach the web port runs commands with unrestricted privileges on the machine hosting vCenter.

YOUR NEXT MOVE

Patch vCenter Server per VMware advisory VMSA-2021-0010 and limit who can reach port 443 on it; then check the host for commands run by the web service.

Read the risk

THE VITAL STATS
CVSS score
9.8/ 10
CVSS v3.1
EPSS probability
100%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Yes — CISA KEV
CVE published
2021-05-26
Added to KEV
2021-11-03
Exploit published
Yes
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190
Severity
critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attacker needsNetwork access to port 443 on the vCenter Server. The affected plug-in is enabled by default. No credentials needed.

Behind the card

4 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
title, summary, cvss, severity, exploitation.attack_complexity, exploitation.prerequisites, exploitation.exploit_available, referencesnvd.nist.gov2026-08-07claude-codehigh
exploitation.known_exploited, remediation.patch_availablecisa.gov2026-08-07claude-codehigh
epssapi.first.org2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2021-21985 · CRDS 0.1 · Issued 2026-08-07