
CISA Adds Three Vulnerabilities to KEV Catalog, Including Omnissa Workspace One UEM Flaw
CybersecurityCISAKEVVulnerabilitiesCVE-2021-22054OmnissaWorkspaceOneUEMSSRFExploitationSolarWindsIvanti
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on Monday, citing evidence of active exploitation. Among the listed flaws is CVE-2021-22054 (CVSS score: 7.5), a server-side request forgery (SSRF) vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM). The notice highlights that these vulnerabilities are being actively targeted, though specific attack vectors or threat actors are not detailed. No additional CVEs or affected products (SolarWinds, Ivanti) were fully described in the provided excerpt. The update underscores the urgency of addressing these flaws due to confirmed exploitation in the wild.