PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-22954 VMware CVE debrief

CVE-2022-22954 is a VMware Workspace ONE Access and Identity Manager server-side template injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-14. Because it is confirmed in KEV and marked as having known ransomware campaign use, organizations running the affected VMware products should treat it as a high-priority remediation item and follow vendor update guidance without delay.

Vendor
VMware
Product
Workspace ONE Access and Identity Manager
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-04-14
Original CVE updated
2026-09-26
Advisory published
2026-09-26
Advisory updated
2026-09-26

Who should care

Security and infrastructure teams responsible for VMware Workspace ONE Access and VMware Identity Manager deployments, especially internet-facing instances or systems that support authentication and identity workflows.

Technical summary

The official records describe this issue as a server-side template injection vulnerability in VMware Workspace ONE Access and Identity Manager. The CISA KEV entry indicates it is a known exploited vulnerability and notes known ransomware campaign use. The supplied source corpus does not provide version ranges, exploit mechanics, or remediation specifics beyond applying updates per vendor instructions.

Defensive priority

Critical priority for exposure reduction and patching. KEV status means active exploitation is already confirmed, and CISA assigned a 2022-05-05 due date after the 2022-04-14 listing.

Recommended defensive actions

  • Apply VMware updates per vendor instructions as soon as possible.
  • Inventory all Workspace ONE Access and Identity Manager deployments, including test and fallback systems.
  • Verify whether any internet-facing or externally reachable instances exist and prioritize them first.
  • Review authentication logs and administrative activity for suspicious access around the exposure window.
  • If patching cannot be completed immediately, reduce exposure by limiting network access to the management and authentication interfaces.
  • Validate that no unapproved changes were made to the affected VMware systems after remediation.

Evidence notes

This debrief is based only on the supplied official sources: the CISA Known Exploited Vulnerabilities JSON entry and linked official CVE/NVD references. The corpus confirms the vulnerability name, vendor/product, KEV listing date (2022-04-14), due date (2022-05-05), and known ransomware campaign use. No CVSS score, affected version range, or exploit details were provided in the supplied material.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-22954 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-22954

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-22954 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-22954

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.first.org/epss/

    first_epss

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.