LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22054: Omnissa Workspace ONE Server-Side Request Forgery

RBRecent Breaches Vulnerability Intelligence·Mar 9, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22054 to its Known Exploited Vulnerabilities catalog on Mar 9, 2026, with a federal patch deadline of Mar 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send…

Omnissa Workspace ONE UEM, formerly VMware Workspace ONE UEM, contains a server-side request forgery vulnerability tracked as CVE-2021-22054. A malicious actor with network access to the UEM instance can send requests without authentication and obtain sensitive information.

The issue belongs to the class of server-side request forgery weaknesses and affects organizations that rely on this product for endpoint and device management.

How it works

CWE-918 describes server-side request forgery, in which an application accepts attacker-controlled input and uses it to construct outbound requests from the server itself. In this case the flaw permits an unauthenticated actor who can reach the UEM service to cause the server to issue requests that would otherwise be restricted, potentially exposing internal resources or data reachable from the server.

Am I affected? How to find it in your systems

Workspace ONE UEM is typically deployed in enterprise environments to manage mobile devices, desktops, and applications. Inventory begins with identifying all installations or cloud tenants of Omnissa Workspace ONE UEM (or its former VMware branding) that are reachable from untrusted networks.

How to remediate

Apply mitigations per the vendor instructions. The primary action is to install the update or configuration change released by Omnissa (formerly VMware) that addresses CVE-2021-22054.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure by limiting network access to the UEM instance to only trusted management networks. Consider placing the service behind an additional access-control layer or web-application firewall that enforces authentication on all endpoints that accept external input.

If your data may have been exposed

Server-side request forgery vulnerabilities that permit unauthenticated access have been used to obtain sensitive information in other products. Organizations should assume that successful exploitation could result in data exposure and should review access logs for the UEM instance. Readers can run a free exposure scan of their email addresses against known breach data to check for prior incidents involving their domains.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOmnissa · Workspace One UEM
WeaknessCWE-918
Added to CISA KEVMar 9, 2026
Federal patch deadlineMar 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities