The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Use CWE-22, Vmware vendor hub and Cloud Foundation product page to widen CVE-2021-21972 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-22224, CVE-2025-22225 and CVE-2026-22719 for nearby disclosures in the same product family.