VMware ESXi
CVE-2020-3992
Why this is on the list
Published on CISA Known Exploited Vulnerabilities evidence. Exploitation is confirmed by CISA; the exact affected version range and vendor fixed build are not yet vendor-confirmed. Remediation follows CISA's required action. This entry upgrades automatically when the vendor advisory is ingested.
- CISA added this to its Known Exploited Vulnerabilities Catalog on 2021-11-03.
- CISA records it as having been used in ransomware campaigns.
Does this apply to your version?
An affected range is on record, derived from CISA's exploitation evidence rather than published by the product's vendor. Check your own release against it, or enter it in the lookup and Patient Protect will evaluate it for you.
Affected: VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG)
Check your versionWhat to do
Apply the vendor-fixed release or documented mitigation as a priority; this vulnerability is known to be exploited.
- Vendor
- VMware
- Product
- VMware ESXi
- Affected versions
- VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG)
- First published
- 2026-09-05
Where this comes from
2 sources- CISAPrimary government source
Confirms active exploitation · Informs severity
Vulnerability is exploited in the wild (CISA KEV listing)
Read the CISA record - FIRSTSupporting intelligence
Informs severity
EPSS estimates a 83% probability that this vulnerability will be exploited in the next 30 days. It is a forecast about the vulnerability, not a statement about whether your installation is affected.
About EPSS
How this was assessed
- CVE-2020-3992 triggered rule KEV_KNOWN_EXPLOITED
- CISA KEV lists it as known-exploited
- EPSS 0.83015
- no affected version range is available for the mapped product
- Patient Protect score 66.6 (HIGH) under pp-risk-1.0
- remediation provenance: PP_TEMPLATE
- evidence incomplete
Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.
Do you run this?
Check your own version against the ledger — it may or may not fall inside the affected range.
Check your technology