Sploitus Critical Vulnerabilities in VMware Workspace ONE Exploited
Article Content
- •CVE-2022-22972 allows authentication bypass in VMware products.
- •CVE-2022-22954 has a CVSS score of 9.8, indicating critical severity.
- •Both vulnerabilities have public PoC code available for exploitation.
Two critical vulnerabilities, CVE-2022-22972 and CVE-2022-22954, affect VMware Workspace ONE and related products. CVE-2022-22972 allows attackers to bypass authentication in vRealize Automation 7.6, while CVE-2022-22954 has a CVSS score of 9.8, indicating severe risk. The attack method for CVE-2022-22972 involves manipulating HTTP headers to authenticate as a compromised user. Affected systems include VMware Workspace ONE, vIDM, and vRealize Automation versions 7.6. Both vulnerabilities have been publicly disclosed, with proof-of-concept (PoC) code available for exploitation. Current reports indicate that CVE-2022-22954 has been actively exploited in the wild since its addition to the CISA KEV list. Organizations using affected VMware products are urged to take immediate action to mitigate risks. The situation remains critical as attackers may leverage these vulnerabilities for unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2022-22954 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Remote Code Execution Vulnerability in VMware Workspace ONE Access A critical remote code execution (RCE) vulnerability, CVE-2022-22954, affects VMware Workspace ONE Access and Identity Manager through server-side template injection (SSTI). The vulnerability was first published on April 11, 2022, and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on April 14…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…