CVE-2025-41250: VMware Cloud Foundation
High severity, CVSS 8.5. EPSS: 0.6% chance of exploitation in the next 30 days.
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
Affected products
- VMware Cloud Foundation: from 9.x.x.x, before 9.0.1.0 (fixed in 9.0.1.0); from 5, before 5.2.2 (fixed in 5.2.2); from 4.5, before 4.6 (fixed in 4.6)
- VMware Telco Cloud Infrastructure
- VMware Telco Cloud Platform
- VMware vCenter: from 8.0, before 8.0 U3g (fixed in 8.0 U3g); from 7.0, before 7.0 U3w (fixed in 7.0 U3w)
- VMware Vsphere Foundation: from 9.x.x.x, before 9.0.1.0 (fixed in 9.0.1.0)
Published 2025-09-29. Last modified 2026-06-17.