Further to our Security Alert (A21-05-14), active exploitation and proof-of-concept against the remote code execution vulnerability (CVE-2021-21985) in VMware vCenter Server and VMware Cloud Foundation have been observed. System administrators are advised to take immediate actions to patch your affected systems to mitigate the elevated risk of cyber attacks.
VMware vCenter Server (vCenter Server)
VMware Cloud Foundation (Cloud Foundation)
Depending on the vulnerabilities being exploited, a successful exploitation of the vulnerabilities could lead to remote code execution and security restriction bypass on the affected system.
Patches for affected products are available. System administrators of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.