CVE-2026-22927Disclosure(microsoft / windows)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows
  • workspace_one_tunnel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-08); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
windowsworkspace_one_tunnel

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Active Exploitation · 2026-07-09: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 107-0807-0907-10
Signal classification3 categories
Disclosure
133.3%
Active Exploitation
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-091
Active Exploitation1
2026-07-101
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-22927 Omnissa Workspace ONE Tunnel for Windows - Local Privilege Escalation (CVSS 7.8) Path traversal flaw (CWE-22) allows authenticated attackers to escalate privileges. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/4fvxKnJJv1

    Post summary

    CVE-2026-22927 is a CVSS 7.8 path‑traversal local privilege escalation flaw in Omnissa Workspace ONE Tunnel for Windows, and a patch is urgently recommended.

    0000075
    71 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Omnissa Workspace ONE Tunnel for Windows (CVE-2026-22927) https://vuldb.com/vuln/376851/cti

    Post summary

    The post notes that CVE-2026-22927 is being actively targeted by multiple offensive actors, indicating real‑world exploitation.

    00000134
    2.3K followersView on X
  • Ferroque Systems Inc.@FerroqueSystems
    Disclosure

    A high-severity vulnerability has been identified in Omnissa Workspace ONE® Tunnel for Windows(CVE-2026-22927). This local privilege escalation vulnerability allows a malicious actor with local access to a device to elevate privileges if left unpatched. https://ferrosys.co/3RlqSOG https://t.co/tlD1HQeUgc

    Post summary

    The tweet announces a high‑severity local privilege escalation vulnerability (CVE‑2026‑22927) in Omnissa Workspace ONE® Tunnel for Windows.

    0000064
    178 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Appomnissaworkspace_one_tunnel---

Explore more