ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

criticalVulnerability exploited in the wildimportance 60CVE-2021-22054CVE-2025-26399CVE-2026-1603

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-22054
Unauthenticated SSRF in VMware (Omnissa) Workspace ONE UEM Console

VMware (now Omnissa) Workspace ONE UEM console, in the 20.0.8, 20.11.0, 21.2.0 and 21.5.0 release lines before their fixed builds, contains a server-side request forgery flaw (CWE-918). A malicious actor with network access to the UEM console can trigger it by sending crafted, unauthenticated requests, causing the console to issue requests on the attacker's behalf. Successful exploitation can give the attacker access to sensitive information reachable from the console (high confidentiality impact, with no integrity or availability impact per the CVSS score). Organizations running an affected Workspace ONE UEM console deployment are exposed, with risk concentrated on consoles reachable from untrusted networks. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-09, EPSS assigns a 97.4% probability of exploitation within 30 days (100th percentile), and reporting describes a coordinated SSRF exploitation surge involving 400+ source IPs.

Do: Upgrade the Workspace ONE UEM console to the fixed builds — 20.0.8.37, 20.11.0.40, 21.2.0.27, or 21.5.0.37 (or later). Until patched, restrict network access to the console (management networks/VPN only, no direct internet exposure) and review logs for unauthenticated or anomalous outbound requests from the console, especially given the reported coordinated SSRF exploitation wave from 400+ IPs. Organizations subject to federal BOD 22-01 must apply vendor mitigations or the prescribed cloud-service guidance.

7.597% KEV
  • vmware (Omnissa) Workspace ONE UEM console 20.0.8 prior to 20.0.8.37
  • vmware (Omnissa) Workspace ONE UEM console 20.11.0 prior to 20.11.0.40
  • vmware (Omnissa) Workspace ONE UEM console 21.2.0 prior to 21.2.0.27
  • +1 more
largeon the order of tens of thousands of on-premises UEM console deployments (estimate)
CVE-2025-26399
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains an unauthenticated deserialization of untrusted data vulnerability (CWE-502) in its AjaxProxy component that allows remote attackers to run arbitrary commands on the host machine without any credentials or user interaction. It is triggered by sending a crafted request to the AjaxProxy endpoint of an affected Web Help Desk installation. Successful exploitation yields full code execution on the server, and the flaw is known to be used in ransomware campaigns. Any organization running SolarWinds Web Help Desk is affected, including installations already patched for the earlier CVE-2024-28988 and CVE-2024-28986, since this flaw is a patch bypass of both. The flaw carries a very high exploitation probability (EPSS ~89.5%) and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09 with known ransomware use.

Do: Immediately apply SolarWinds' hotfix for CVE-2025-26399 per the vendor's instructions — organizations that previously patched CVE-2024-28988 or CVE-2024-28986 must apply the new hotfix because those patches do not close this flaw. If the hotfix cannot be applied right away, restrict network access to Web Help Desk (firewall/VPN, limit exposure of the service to the internet) and discontinue use if mitigations are unavailable, per CISA KEV/BOD 22-01 guidance. Given known ransomware use, review Web Help Desk hosts for signs of compromise, including unexpected process execution and accounts or data accessed via the server.

9.890% KEV ransomware
  • SolarWinds Web Help Desk
moderatelow thousands of internet-exposed Web Help Desk instances, with a total on-prem install base plausibly in the tens of thousands
CVE-2026-1603
Authentication Bypass in Ivanti Endpoint Manager Leaks Stored Credentials

CVE-2026-1603 is an authentication bypass (CWE-288/CWE-306) in Ivanti Endpoint Manager (EPM) that affects versions before 2024 SU5. A remote, unauthenticated attacker can send crafted network requests to a vulnerable EPM core server without valid credentials. Successful exploitation grants read access to specific stored credential data held by EPM, which could be leveraged for further access within the environment. Any organization running an EPM deployment on a version earlier than 2024 SU5 is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09, confirming active exploitation in the wild, and its EPSS score of 80.6% (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known, suggesting private exploit use.

Do: Upgrade EPM core servers to version 2024 SU5 (or later) as soon as possible, in line with CISA's KEV and BOD 22-01 timelines, which have been shortened for this flaw. Until patched, restrict internet-facing exposure of EPM services and review EPM servers for anomalous authentication activity or signs of stored-credential access. If mitigations are unavailable, follow CISA's guidance to apply vendor-recommended mitigations or discontinue use of the affected product.

7.581% KEV
  • Ivanti Endpoint Manager (EPM) all versions before 2024 SU5
largetens of thousands of EPM core-server deployments (order of 10,000–100,000 installations), an estimate
Full article383 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 10, 2026Vulnerability / Enterprise Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerability list is as follows -

  • CVE-2021-22054 (CVSS score: 7.5) - A server-side request forgery (SSRF) vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM) that could allow a malicious actor with network access to UEM to send requests without authentication and to gain access to sensitive information.
  • CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine.
  • CVE-2026-1603 (CVSS score: 8.6) - An authentication bypass using an alternate path or channel vulnerability in Ivanti Endpoint Manager that could allow a remote unauthenticated attacker to leak specific stored credential data.

The addition of CVE-2025-26399 comes in the wake of reports from Microsoft and Huntress that threat actors are exploiting security flaws in SolarWinds Web Help Desk to obtain initial access. The activity is believed to be the work of the Warlock ransomware crew.

CVE-2021-22054, on the other hand, was flagged by GreyNoise in March 2025 as being exploited in conjunction with several other SSRF vulnerabilities in other products as part of a coordinated campaign.

There are currently no details on how CVE-2026-1603 is being weaponized in the wild, although Defused Cyber noted in a post on X last month that it's seeing active exploitation efforts targeting the flaw. The attack originated from the IP address 103.69.224[.]98.

As of writing, Ivanti's security bulletin has not been updated to reflect the exploitation status. The company said it's not aware of any customers being exploited by the vulnerability.

To counter the risk posed by active threats, Federal Civilian Executive Branch (FCEB) agencies have been ordered to apply the fix for SolarWinds Web Help Desk by March 12, 2026, and the remaining two by March 23, 2026.

"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html