CVE-2025-41241: VMware Cloud Foundation
Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.
VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.
Affected products
- VMware Cloud Foundation
- VMware Telco Cloud Infrastructure: from 2, before 3 (fixed in 3)
- VMware Telco Cloud Platform
- VMware vCenter: from 8.0, before 8.0 U3g (fixed in 8.0 U3g); from 7.0, before 7.0 U3v (fixed in 7.0 U3v)
Published 2025-07-29. Last modified 2026-06-17.