SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22054

Omnissa Workspace ONE Server-Side Request Forgery

KEVHIGH 7.5EPSS 97.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 23 March 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
97.37% probability · 100th percentile
CISA KEV
Listed 9 March 2026 · due 23 March 2026
Weakness
CWE-918
Affected
vmware/workspace one uem console
Source
security@vmware.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html ; https://nvd.nist.gov/vuln/detail/CVE-2021-22054

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.