Critical RCE Vulnerability Discovered in VMware vCenter Server May 26, 2021 11:32 GMT · Comment VMware VMware has released fixes to address a significant vulnerability in vCenter System that can be exploited by an attacker to execute arbitrary code on the server. The vulnerability, identified as CVE-2021-21985 (CVSS score 9.8), originates from a lack of input validation in the Virtual SAN (vSAN) plug-in Health Check. This plug-in is enabled by default in vCenter Server. VMware said in its advisory that "A malicious actor with network access to port 443 may exploit th...