logo

High Severity VMware Vulnerabilities Under Active Exploitation

ID: 959cb6c7-2105-536d-8419-de3875167025

STIX ID: report--959cb6c7-2105-536d-8419-de3875167025

Feed Name: Kudelski Security

Threat Score
78/100

Date Published: 2022-05-20

Date Updated: 2026-07-22

...
...

This bulletin summarizes VMware advisories from April and May 2022 (VMSA-2022-0011 and VMSA-2022-0014), detailing multiple critical vulnerabilities—including remote code execution (e.g., CVE-2022-22954), authentication bypass (e.g., CVE-2022-22972 and OAuth2 ACS bypass CVE-2022-22955/22956), and local privilege escalation (e.g., CVE-2022-22960/22973)—some of which have been actively exploited; CISA issued an emergency directive requiring rapid patching and the report strongly recommends applying VMware patches rather than temporary workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.