CVE-2025-41225: VMware Cloud Foundation
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
Affected products
- VMware Cloud Foundation
- VMware Telco Cloud Infrastructure
- VMware Telco Cloud Platform
- VMware vCenter Server: from 8.0, before 8.0 U3e (fixed in 8.0 U3e); from 7.0, before 7.0 U3v (fixed in 7.0 U3v)
Published 2025-05-20. Last modified 2026-06-17.