PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-22054 Omnissa CVE debrief

CVE-2021-22054 is a server-side request forgery (SSRF) issue associated with Omnissa Workspace ONE UEM. In the supplied corpus, CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-09 and set a remediation due date of 2026-03-23. Because CISA classifies it as a KEV item, defenders should treat it as time-sensitive and follow the vendor and CISA remediation guidance provided in the source record.

Vendor
Omnissa
Product
Workspace One UEM
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2026-03-09
Original CVE updated
2026-03-09
Advisory published
2026-03-09
Advisory updated
2026-03-09

Who should care

Security, platform, and application teams responsible for Omnissa Workspace ONE UEM deployments; cloud-service operators; and incident responders tracking CISA KEV items.

Technical summary

The supplied source item identifies CVE-2021-22054 as an SSRF affecting Omnissa Workspace ONE UEM. CISA’s KEV entry directs defenders to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. The corpus does not provide a CVSS score or further technical breakdown, so this debrief is limited to the KEV designation and remediation guidance.

Defensive priority

Urgent

Recommended defensive actions

  • Confirm whether Omnissa Workspace ONE UEM is deployed in your environment and map all affected instances.
  • Apply vendor-provided mitigations and validate that they are in place.
  • If the service is cloud-based where applicable, follow CISA BOD 22-01 guidance.
  • If mitigations are unavailable or cannot be validated, discontinue use of the product or remove exposure as directed by CISA.
  • Track remediation against the KEV due date in the supplied corpus: 2026-03-23.

Evidence notes

The source corpus contains a CISA KEV machine-readable entry for CVE-2021-22054 with vendorProject=Omnissa, product=Workspace One UEM, vulnerabilityName=Omnissa Workspace ONE Server-Side Request Forgery, dateAdded=2026-03-09, dueDate=2026-03-23, and requiredAction text pointing to vendor mitigations, BOD 22-01 guidance for cloud services, or discontinuation if mitigations are unavailable. The metadata also references an archived VMware security advisory and the NVD detail page, but the corpus does not include a CVSS score or additional exploit details.

Official resources

This debrief is based only on the supplied source corpus and official record links. It avoids exploit instructions, proof-of-concept details, and unsupported claims. Dates and KEV timing reflect the provided CVE/source metadata.