tag
ESXi
CVE-2024-37085
network
MEDIUM 6.8
KEV
Ransomware
EPSS 26%
VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)
CVE-2024-37085 is an authentication bypass in domain-joined VMware ESXi environments where AD group membership manipulation can grant administrator-level ESXi access without valid local ESXi credentials. Public reporting links this issue to real-world…
Patched
2026-05-16