CVE-2021-22054Active Exploitation(vmware / workspace_one_uem_console)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch vmware workspace_one_uem_console systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • workspace_one_uem_console

Threat summary

  • Active exploitation appears in 10 classified signals
  • Patch or workaround signal is available
  • 22 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 10 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 13 signals
  • General: 6 classified signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 9 mentions (2026-03-10); latest day: 1
  • 22 total mentions across 7 days

Affected systems

Vendors
Products
workspace_one_uem_console

Deep dive

Activity timeline22 mentions / 7d
02579Mentions · 2026-03-09: 5Mentions · 2026-03-10: 9Mentions · 2026-03-11: 2Mentions · 2026-03-13: 2Mentions · 2026-03-23: 2Mentions · 2026-03-31: 1Mentions · 2026-06-11: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 6Active Exploitation · 2026-03-11: 2Active Exploitation · 2026-06-11: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 4Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 6Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-31: 103-0903-1003-1103-1303-2303-3106-11
Signal classification4 categories
Active Exploitation
1045.5%
General
627.3%
Disclosure
418.2%
Patch
29.1%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-03-095
Active Exploitation1Disclosure1General2Patch1
2026-03-109
Active Exploitation6Disclosure2Patch1
2026-03-112
Active Exploitation2
2026-03-132
Disclosure1General1
2026-03-232
General2
2026-03-311
General1
2026-06-111
Active Exploitation1
Full discourse20 posts
  • CISA Cyber@CISACyber
    General

    🛡️ We added Omnissa Workspace ONE UEM vulnerability CVE-2021-22054, SolarWinds Web Help Desk vulnerability CVE-2025-26399, & Ivanti Endpoint Manager vulnerability CVE-2026-1603 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/fcNCCfmzdF

    Post summary

    The tweet announces inclusion of three CVEs (CVE‑2021‑22054, CVE‑2025‑26399, CVE‑2026‑1603) in the DHS KEV catalog and directs readers to a link for further information.

    11204216.8K
    292.6K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/9追加) 🛡️No.1538 CVE-2021-22054 Omnissa Workspace ONE Server-Side Request Forgery ============= CVSSスコア: 7.5 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / CISA-ADP) 深刻度:重要 国内影響度判定(※):中 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから細工されたリクエストを介して、機密情報にアクセスされる恐れがあります。(旧称:VMware Workspace One UEM) https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html 🛡️No.1539 CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / CISA-ADP) 深刻度:緊急🔥 国内影響度判定(※):高 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホスト マシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399 🛡️No.1540 CVE-2026-1603 Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability ============= CVSSスコア: 8.6 (Base) / ivanti CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:代替パスまたはチャネルを使用した認証回避 (CWE-288 / ivanti) 深刻度:重要 国内影響度判定(※):中~高 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから特定の保存された資格情報データを窃取される恐れがあります。 https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024 ※ ChatGPTによる判定結果。試験的に行っているもので、誤判定の可能性があります。 CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/09/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has confirmed that three CVEs—CVE‑2021‑22054, CVE‑2025‑26399, and CVE‑2026‑1603—are actively being exploited, and the cited vendor advisories provide patch or mitigation guidance.

    020623.8K
    42.7K followersView on X
  • ET Labs@ET_Labs
    General

    35 new OPEN, 39 new PRO (35 + 4) LandUpdate808, SoftEther VPN, Xeox RMM, TA402, TA473, TA453, UNK_NightOwl, UNK_RobotDreams, VMware (CVE-2021-22054) https://community.emergingthreats.net/t/ruleset-update-summary-2026-03-13-v11146/3231

    Post summary

    A ruleset update note listing new items, including VMware’s CVE-2021-22054, without providing exploitation details or mitigation information.

    03020351
    5.7K followersView on X
  • CyberThreatIntel@IPSecOSINT
    Patch

    🚨 CYBER: CISA adds CVE-2021-22054 A pre-authentication Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to make arbitrary HTTP requests. Patch now to safeguard US networks. https://go.dhs.gov/Z3Q #Cybersecurity #KEV https://t.co/i3XeeP8dcU

    Post summary

    The tweet announces that CISA has added CVE-2021-22054, an SSRF flaw that permits unauthenticated HTTP requests, and urges immediate patching to protect U.S. networks.

    0003060
    15 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Mar 9) CVE-2021-22054 Omnissa Workspace ONE サーバー側リクエストフォージェリ CVE-2025-26399 SolarWinds Webヘルプデスクにおける信頼できないデータのデシリアライゼーションの脆弱性 CVE-2026-1603 Ivanti Endpoint Manager (EPM) の認証バイパスの脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/09/cisa-adds-three-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has identified three CVEs with confirmed wild‑world exploitation and added them to its catalog, but the notice provides no PoC, exploit code, or patch details.

    00020312
    4.7K followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2021-22054 (EPSS 94.00%) VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain a hypervelocity detec Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2021-22054 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post notes EPSS risk and affected VMware Workspace ONE UEM console versions but offers no PoC, exploit, active usage, or mitigation info.

    1000056
    311 followersView on X
  • Zero-sum@projectzerosum
    Disclosure

    2/ One confirmed issue is CVE-2021-22054 in Workspace ONE UEM, an SSRF bug. SSRF is rarely “just a web bug.” It can expose internal services, cloud metadata, and management paths defenders assumed were unreachable.

    Post summary

    The message confirms the existence of an SSRF vulnerability (CVE-2021-22054) in Workspace ONE UEM and highlights potential internal exposure risks.

    1000057
    28 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Active Exploitation

    CISA、既知の悪用された脆弱性3件をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/03/09/cisa-adds-three-known-exploited-vulnerabilities-catalog CVE-2021-22054 Omnissa Workspace ONE サーバー側リクエストフォージェリ CVE-2025-26399 SolarWinds Webヘルプデスクにおける信頼できないデータのデシリアライゼーションの脆弱性

    Post summary

    CISA has updated its catalog to include three CVEs that are confirmed to be actively exploited, providing brief vulnerability type details but no proof‑of‑concept or patch information.

    10000121
    49 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2021-22054 - n/a - VMware Workspace ONE UEM console - https://www.redpacketsecurity.com/cve-alert-cve-2021-22054-n-a-vmware-workspace-one-uem-console/ #OSINT #ThreatIntel #CyberSecurity #cve-2021-22054 #n-a #vmware-workspace-one-uem-console

    Post summary

    A brief tweet linking a CVE alert about CVE-2021-22054 affecting VMware Workspace ONE UEM console, with no additional technical, exploit, or remediation details.

    00010112
    3.5K followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-22054 Omnissa Workspace ONE Server-Sid @CISACyber https://www.rfr.bz/t494d18

    Post summary

    CISA reports CVE‑2021‑22054 as actively exploited and adds it to the KEV catalog, without mentioning a PoC, patch, or technical details.

    0000027
    1.5K followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2021-22054 (EPSS 94.00%) VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 cont Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2021-22054 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The tweet highlights the high EPSS score for CVE-2021-22054 and affected versions, but offers no concrete details about the vulnerability itself, exploitation, or remediations.

    0000051
    310 followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2021-22054 (EPSS 94.00%) VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 cont Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2021-22054 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The tweet highlights a high EPSS score for CVE‑2021‑22054, implying a strong exploitation likelihood, but provides no PoC, exploit code, or evidence of active attacks.

    0000067
    310 followersView on X
  • Nicolas Coolman@NicolasCoolman
    Disclosure

    CVE-2021-22054 : Urgence CISA sur la faille SSRF d’Omnissa Workspace ONE https://zoneantimalware.com/cisa-alerte/

    Post summary

    A CISA emergency alert is issued for the SSRF vulnerability CVE‑2021‑22054 in Omnissa Workspace ONE, without any mention of PoC, exploit code, patches, or active exploitation.

    0000032
    84 followersView on X
  • securityrss.ai@securityRSS
    Active Exploitation

    CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog due to active exploitation: 1. CVE-2021-22054 (CVSS 7.5) - SSRF in Omnissa Workspace One UEM. 2. CVE-2025-26399 (CVSS 9. https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html

    Post summary

    The statement announces that CISA has classified three CVEs as actively exploited in the wild, providing some technical details but no PoC, exploit code, or patch information.

    00000110
    76 followersView on X
  • SecAlerts@SecAlertsCo
    Active Exploitation

    CISA adds 3 x exploited vulns to KEV catalog. Info, incl. fix info, at SecAlerts: CVE-2025-26399: https://secalerts.co/vulnerability/CVE-2025-26399 CVE-2026-1603: https://secalerts.co/vulnerability/CVE-2026-1603 CVE-2021-22054: https://secalerts.co/vulnerability/CVE-2021-22054 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CISA https://t.co/be8GzJiRrL

    Post summary

    CISA’s KEV catalog now includes three exploited CVEs (2025‑26399, 2026‑1603, and 2021‑22054) with fix information linked via SecAlerts.

    00000148
    802 followersView on X
  • Fernando Karl@fernandokarl
    Disclosure

    🚨 Atenção, profissionais de segurança! A CVE-2021-22054 afeta o Omnissa Workspace ONE, permitindo SSRF que expõe informações sensíveis. Aplique as mitigações recomendadas pelo fornecedor ou considere descontinuar o uso do produto. Proteja seus dados! #CyberSecurity #InfoSec #CVE

    Post summary

    The post announces CVE‑2021‑22054, a Server Side Request Forgery flaw in Omnissa Workspace ONE that exposes sensitive data, and recommends applying vendor‑provided mitigations or discontinuing the product.

    0000038
    257 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA added CVE-2021-22054, CVE-2025-26399, and CVE-2026-1603 to its Known Exploited Vulnerabilities list due to active attacks. Issues affect SolarWinds Web Help Desk, Ivanti, and Workspace One with federal patch deadlines in 2026. #SolarWinds #Ivanti https://ift.tt/zAeDFtB

    Post summary

    CISA has added CVE-2021-22054, CVE-2025-26399, and CVE-2026-1603 to its Known Exploited Vulnerabilities list, citing active attacks against SolarWinds Web Help Desk, Ivanti, and Workspace One, with federal patch deadlines set for 2026.

    00000196
    3.7K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    CISA adds Ivanti Endpoint Manager, SolarWinds Web Help Desk, VMware Workspace ONE flaws (CVE-2025-26399, CVE-2026-1603, CVE-2021-22054) to KEV list amid active exploitation. Patch now. https://threatcluster.io/cluster/active-exploitation-of-vulnerabilities-in-ivanti-and-solarwi-a735cf92

    Post summary

    CISA has added three CVEs (CVE-2025-26399, CVE-2026-1603, CVE-2021-22054) to the KEV list because they are being exploited in the wild, and patches are now available.

    00000119
    99 followersView on X
  • Mr.Yang | 科技趋势@Sxsyer
    Patch

    大多数人盯着金价和油价,但接下来30天,真正会先变贵的,可能是“安全交付能力”。 今天下午我盯了一圈公开漏洞目录,看到一个细节:SolarWinds Web Help Desk 相关漏洞(CVE-2025-26399)的官方处置截止日就在3月12日,已经进了最后48小时窗口。同批还有 Omnissa Workspace One UEM(CVE-2021-22054)和 Ivanti EPM(CVE-2026-1603)在排队。这个信号不只是技术圈新闻,它会往供应链和项目报价里传导。 我的判断很明确: 这轮不是“谁技术最强”赢,而是“谁能最快给出可验证修复证据”赢。 为什么?看三个正在发生的变化: 1)甲方采购口径在变。 过去很多项目只看功能、价格、周期;现在越来越多会加一条:补丁闭环能力。你有没有资产清单?有没有责任人?有没有ETA?有没有工单号和版本号证据?这些以前是加分项,现在正在变成入场券。 2)交付节奏会被安全节点反向定义。 以前是产品节奏带安全;现在是安全节点卡产品节奏。一个关键组件未修复,可能不是“延期一天”,而是整条验收链条暂停。对做系统集成、工业软件、设备运维的人来说,这就是现金流问题,不是“技术洁癖”。 3)价格体系会出现分层。 同样做数字化、同样做AI改造,能拿出“72小时内补丁闭环+证据留痕”的团队,报价会更硬。另一些团队会陷入低价竞争,因为他们只能承诺“我们会尽快处理”,但拿不出证据链。 这事和大宗商品有什么关系? 关系很直接:当不确定性上升,市场会给“确定性交付”更高溢价。原材料的波动大家看得见,合规与安全的隐形成本很多人还没开始计价。等普遍计价那天,利润空间已经被重新分配完了。 如果你是老板,今天就做三件小事: - 拉一张“关键系统暴露清单”:有没有 SolarWinds / Omnissa / Ivanti 相关资产,先把有无说清楚。 - 给每个高风险项写明 owner 和截止时间,不要写“尽快”。 - 所有修复都留证据:版本、工单、时间戳。没有证据,等于没做。 我再说得更直白一点: 2026年,很多订单看起来是在比功能,实际在比风险控制能力。 能把风险收敛成证据的人,会拿走更高质量的客户。 你现在的项目里,安全修复是“顺手做”,还是已经进入“交付主流程”了?

    Post summary

    The post stresses the crucial need to meet the official mitigation deadline for CVE‑2025‑26399, emphasizing that verifiable patch evidence will become a key factor in procurement and market positioning.

    00000196
    290 followersView on X
  • Cyber Cachce | بالعربي@Cybercachear
    Active Exploitation

    📌 أضافت وكالة الأمن السيبراني الأمريكية (CISA) ثلاث ثغرات إلى قائمة الثغرات المعروفة المستغلة (KEV) بسبب وجود استغلال نشط، وتشمل ثغرات في SolarWinds وIvanti وWorkspace One. من بينها CVE-2021-22054، ثغرة SSRF بقيمة CVSS 7.5 في Omnissa Workspace One UEM (المعروف سابقاً بـ VMware… https://t.co/A6hno74lZk

    Post summary

    CISA has added CVE-2021-22054, an SSRF vulnerability in Omnissa Workspace One UEM, to its KEV list, highlighting that it is being actively exploited in the wild.

    0000068
    432 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwareworkspace_one_uem_console---

Explore more