Skip to content
Critical Vulnerabilities in VMware Workspace ONE Exploited

Critical Vulnerabilities in VMware Workspace ONE Exploited

First seen 15 Sep 2026, 02:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 04:21 UTC
  • CVE-2022-22972 allows authentication bypass in VMware products.
  • CVE-2022-22954 has a CVSS score of 9.8, indicating critical severity.
  • Both vulnerabilities have public PoC code available for exploitation.

Two critical vulnerabilities, CVE-2022-22972 and CVE-2022-22954, affect VMware Workspace ONE and related products. CVE-2022-22972 allows attackers to bypass authentication in vRealize Automation 7.6, while CVE-2022-22954 has a CVSS score of 9.8, indicating severe risk. The attack method for CVE-2022-22972 involves manipulating HTTP headers to authenticate as a compromised user. Affected systems include VMware Workspace ONE, vIDM, and vRealize Automation versions 7.6. Both vulnerabilities have been publicly disclosed, with proof-of-concept (PoC) code available for exploitation. Current reports indicate that CVE-2022-22954 has been actively exploited in the wild since its addition to the CISA KEV list. Organizations using affected VMware products are urged to take immediate action to mitigate risks. The situation remains critical as attackers may leverage these vulnerabilities for unauthorized access.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2022-04-11
CVE-2022-22954 published
VMware disclosed CVE-2022-22954 affecting multiple Workspace ONE versions.
Sploitus
2022-04-14
CVE-2022-22954 added to CISA KEV
CISA listed CVE-2022-22954 due to active exploitation in the wild.
Sploitus
2022-05-20
CVE-2022-22972 published
VMware disclosed CVE-2022-22972 affecting Workspace ONE and vRealize Automation.
Sploitus
2022-05-29
First public PoC for CVE-2022-22972
A proof-of-concept script was released for exploiting CVE-2022-22972.
Sploitus
2026-09-11
CVE-2022-22954 PoC released
A public PoC script for CVE-2022-22954 was shared, allowing exploitation.
Sploitus
2026-09-14
CVE-2022-22972 PoC released
A proof-of-concept script for CVE-2022-22972 was published, facilitating exploitation.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2022-22954 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed