peter bassill · operator
$ cve CVE-2021-22054 JSON

CVE-2021-22054 KEV

7.5
HIGH · CVSS 3.1 · EPSS 99.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-03-23.

Description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS99.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-918
On CISA KEVyes — remediate by 2026-03-23
Public exploitnone known
Published2021-12-17
Last modified2026-06-17

CISA KEV

NameOmnissa Workspace ONE Server-Side Request Forgery
Added2026-03-09
Due2026-03-23
Vendor / productOmnissa / Workspace One UEM
Ransomware usenone reported

Affected (1)

VendorProduct
vmwareworkspace one uem console

References

→ the Explorer  ·  watch your stack  ·  NVD