piyokango[verified]@piyokangoActive Exploitation
CISA has confirmed that three CVEs—CVE‑2021‑22054, CVE‑2025‑26399, and CVE‑2026‑1603—are actively being exploited, and the cited vendor advisories provide patch or mitigation guidance.
キタきつね[verified]@foxbookActive Exploitation
CISA has identified three CVEs with confirmed wild‑world exploitation and added them to its catalog, but the notice provides no PoC, exploit code, or patch details.
Patrick Roland[verified]@DeusLogicaGeneral
The post notes EPSS risk and affected VMware Workspace ONE UEM console versions but offers no PoC, exploit, active usage, or mitigation info.
Zero-sum[verified]@projectzerosumDisclosure
The message confirms the existence of an SSRF vulnerability (CVE-2021-22054) in Workspace ONE UEM and highlights potential internal exposure risks.
Patrick Roland[verified]@DeusLogicaGeneral
The tweet highlights the high EPSS score for CVE-2021-22054 and affected versions, but offers no concrete details about the vulnerability itself, exploitation, or remediations.
Patrick Roland[verified]@DeusLogicaGeneral
The tweet highlights a high EPSS score for CVE‑2021‑22054, implying a strong exploitation likelihood, but provides no PoC, exploit code, or evidence of active attacks.
ThreatCluster[verified]@threatclusterActive Exploitation
CISA has added three CVEs (CVE-2025-26399, CVE-2026-1603, CVE-2021-22054) to the KEV list because they are being exploited in the wild, and patches are now available.
Mr.Yang | 科技趋势[verified]@SxsyerPatch
The post stresses the crucial need to meet the official mitigation deadline for CVE‑2025‑26399, emphasizing that verifiable patch evidence will become a key factor in procurement and market positioning.