VMware vCenter Server Improper Input Validation Vulnerability
n/a — VMware vCenter Server and VMware Cloud Foundation
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- May 26, 2021
- Modified
- Aug 12, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- Nov 17, 2021
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2021-21985, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Schira4396/VcenterKiller★ 1483
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
updated Aug 30, 2026
- alt3kx/CVE-2021-21985_PoC★ 213
updated Sep 3, 2026
- xnianq/cve-2021-21985_exp★ 115
cve-2021-21985 exploit
updated May 23, 2026
- testanull/Project_CVE-2021-21985_PoC★ 29
updated May 23, 2026
- sknux/CVE-2021-21985_PoC★ 3
VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985)
updated Mar 24, 2026
- daedalus/CVE-2021-21985★ 2
CVE-2021-21985 vmware 6.7-9.8 RCE
updated Nov 15, 2024
- onSec-fr/CVE-2021-21985-Checker★ 2
CVE-2021-21985 Checker.
updated May 5, 2023
- haidv35/CVE-2021-21985★ 1
updated Mar 8, 2023
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2021-21985?
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
How severe is CVE-2021-21985?
CVE-2021-21985 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2021-21985 actively exploited in the wild?
Yes. CVE-2021-21985 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2021-21985?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2021-21985?
Yes - a public Nuclei template referencing CVE-2021-21985 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2021-21985?
CVE-2021-21985 is classified under CWE-918, CWE-20, CWE-470 (CWE-918 Server-Side Request Forgery (SSRF)).
Cross-checked against
Impactr finds and proves whether CVE-2021-21985 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist