Server VMware Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in VMware Server.

Recent VMware Server Security Advisories

Advisory Title Published
2026-08-20 cve-2026-47877 - HIGH - Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) August 20, 2026
2026-08-20 cve-2026-47889 - MEDIUM - Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse August 20, 2026
2026-08-20 cve-2026-47890 - LOW - Spring Framework Server Sent Event stream corruption while rendering fragments August 20, 2026
2026-08-20 cve-2026-47837 - MEDIUM - Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests August 20, 2026
2026-08-20 cve-2026-59270 - CRITICAL - Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces August 20, 2026
2026-08-20 cve-2026-47894 - MEDIUM - Spring Cloud Config Server Native Environment Repository Exposure August 20, 2026
2026-08-20 cve-2026-47844 - MEDIUM - Reactor Netty HTTP Server Leaks Exception Details August 20, 2026
2026-08-20 cve-2026-47845 - MEDIUM - Reactor Netty HTTP Server may incorrectly evaluate proxy addresses August 20, 2026
2026-08-20 cve-2026-47874 - MEDIUM - Reactor Netty HTTP Server Denial of Service With Pipelined Requests August 20, 2026
2026-08-20 cve-2026-47836 - HIGH - Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN August 20, 2026

By the Year

In 2026 there have been 1 vulnerability in VMware Server with an average score of 6.1 out of ten. Last year, in 2025 Server had 1 security vulnerability published. At the current rates, it appears that the number of vulnerabilities last year and this year may equal out. Last year, the average CVE base score was greater by 1.40




Year Vulnerabilities Average Score
2026 1 6.10
2025 1 7.50

It may take a day or so for new Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent VMware Server Security Vulnerabilities

Spring Authorization Server 1.5.0-1.5.7 Open Redirect via request_uri
CVE-2026-59355 6.1 - Medium - August 27, 2026

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.

Open Redirect

Spring Cloud Gateway Webflux Exposes Env Vars via SpEL
CVE-2025-41253 7.5 - High - October 16, 2025

The following versions of Spring Cloud Gateway Server Webflux may be vulnerable to the ability to expose environment variables and system properties to attackers. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server Webflux (Spring Cloud Gateway Server WebMVC is not vulnerable). * An admin or untrusted third party using Spring Expression Language (SpEL) to access environment variables or system properties via routes. * An untrusted third party could create a route that uses SpEL to access environment variables or system properties if: * The Spring Cloud Gateway Server Webflux actuator web endpoint is enabled via management.endpoints.web.exposure.include=gateway and management.endpoint.gateway.enabled=trueor management.endpoint.gateway.access=unrestricte. * The actuator endpoints are available to attackers. * The actuator endpoints are unsecured.

EL Injection

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x
CVE-2009-4811 - April 27, 2010

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\x90 sequence in the USER and PASS commands, a related issue to CVE-2009-3707. NOTE: some of these details are obtained from third party information.

Use of Externally-Controlled Format String

Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5
CVE-2009-3733 - November 02, 2009

Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.

Directory traversal

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x
CVE-2009-3707 - October 16, 2009

VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.

Use of Externally-Controlled Format String

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem
CVE-2009-1072 - March 25, 2009

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

Configuration

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which
CVE-2009-0778 - March 12, 2009

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for VMware Server or by VMware? Click the Watch button to subscribe.

VMware
Vendor

VMware Server
Product

subscribe