The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.
https://github.com/ascii42/check_vmware_cve
https://www.securityweek.com/nato-flagged-vulnerability-tops-latest-vmware-security-patch-batch/