CVE-2026-22722Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-26); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-26: 3Mentions · 2026-02-28: 1Patch / Workaround · 2026-02-26: 2Technical Details · 2026-02-26: 1Technical Details · 2026-02-28: 102-2602-28
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure1Patch2
2026-02-281
Disclosure1
Full discourse4 posts
  • ((yuki)|(kwmt)|(kawaman))@yuki_kawamitsu
    Patch

    Workstation や Fusion のマイナーナンバリングどうするんだ?と、心配してたけど 25H2u1 にするのか... 🤔 VMSA-2026-0002: VMware Workstation and Fusion updates address multiple vulnerabilities (CVE-2026-22715, CVE-2026-22716, CVE-2026-22717, CVE-2026-22722) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36986

    Post summary

    The post announces VMware updates (VMSA‑2026‑0002) that patch several CVEs for Workstation and Fusion, with no mention of PoC, exploits, or active attacks.

    00050352
    1.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22722 A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-… https://www.cve.org/CVERecord?id=CVE-2026-22722

    Post summary

    The text announces CVE-2026-22722, describing a null pointer dereference vulnerability that could be triggered by authenticated users on Windows workstations, but provides no PoC, exploit, or patch details.

    00000167
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22722 Windows Workstation Null Pointer Dereference Vulnerability in CVE-2026-22722 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22722

    Post summary

    The text announces the Windows Workstation null pointer dereference vulnerability identified as CVE-2026-22722, linking to a vulnerability detail page. It provides the vulnerability type but offers no proof‑of‑concept, exploitation details, or remediation information.

    0000039
    4.0K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    VMSA-2026-0002: VMware Workstation and Fusion updates address multiple vulnerabilities (CVE-2026-22715, CVE-2026-22716, CVE-2026-22717, CVE-2026-22722) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36986

    Post summary

    Broadcom released VMware Workstation and Fusion updates to patch multiple CVEs, with no mention of PoC, exploits, or active attacks.

    00000362
    6.7K followersView on X

Explore more