Skip to content
Remote Code Execution Vulnerability in VMware Workspace ONE Access

Remote Code Execution Vulnerability in VMware Workspace ONE Access

First seen 14 Sep 2026, 21:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 22:53 UTC
  • CVE-2022-22954 allows RCE via SSTI in VMware products.
  • PoC code is publicly available, raising exploitation risk.
  • Organizations using affected VMware services must act quickly.

A critical remote code execution (RCE) vulnerability, CVE-2022-22954, affects VMware Workspace ONE Access and Identity Manager through server-side template injection (SSTI). The vulnerability was first published on April 11, 2022, and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on April 14, 2022. Recent proof-of-concept (PoC) code has been released, allowing attackers to exploit this vulnerability. The PoC code enables attackers to execute arbitrary commands on affected systems by leveraging specific queries on services like Shodan and Zoomeye. Security professionals are advised to avoid using this PoC in production environments. The vulnerability has been confirmed to impact numerous organizations using the affected VMware products. As of now, the exploit is publicly available, increasing the urgency for organizations to assess their exposure and apply necessary mitigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2022-04-11
CVE-2022-22954 published
VMware disclosed a remote code execution vulnerability in Workspace ONE Access and Identity Manager.
Sploitus
2022-04-14
CVE added to CISA KEV
CISA included CVE-2022-22954 in its Known Exploited Vulnerabilities catalog due to active exploitation.
Sploitus
2026-09-13
PoC code released
A proof-of-concept script for CVE-2022-22954 was published, demonstrating RCE capabilities.
Sploitus
2026-09-14
Further PoC details released
Another article provided additional details on the PoC for CVE-2022-22954, emphasizing its risks.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2022-22954 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed