US security agency issues emergency alert over vulnerable VMware products
A string of actively exploited critical vulnerabilities across five popular VMware products has been described as an "unacceptable risk" to government systems
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
The US’ Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency advisory instructing all federal agencies to patch or remove a number of actively exploited VMware products.
A total of five different VMware services have been found to be vulnerable to a chained attack that could lead to remote code execution (RCE) and escalation of privileges to root.
CISA said that “these vulnerabilities pose an unacceptable risk” to federal agencies and the situation required “emergency action”.
The authority’s instructions to either patch immediately, or remove the affected products, is mandatory for all federal agencies and highly advised for the private sector.
It’s currently unknown who is exploiting the VMware vulnerabilities, but CISA said it is likely to be an Advanced Persistent Threat (APT) hacking group – a type of group that is often backed by nation-states.
A CISA incident response team has already been deployed to one large organisation that has reported evidence of an attack, and “multiple other large organisations” have also been affected, according to intelligence.
The affected VMware products are VMware Workspace ONE Access (Access), VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Two vulnerabilities in the affected products were patched on 6 April, though CISA said cyber attackers were able to reverse engineer these updates and start exploiting them within 48 hours after the update’s release.
Tracked as CVE-2022-22954 and CVE-2022-22960, the vulnerabilities are RCE and privilege escalation flaws with CVSSv3 severity scores of 9.8 and 7.8 respectively.
VMware released patches for two additional vulnerabilities on Wednesday, tracked as CVE-2022-22972 and CVE-2022-22973.
The first is an authentication bypass flaw in VMware Workspace ONE Access, Identity Manager, and vRealize Automation and has the more serious severity score of 9.8. CVE-2022-22973 is a local privilege escalation vulnerability in VMware Workspace ONE Access, and its Identity Manager suite.
CISA believes that the same APT group may try to reverse engineer these two new vulnerabilities and combine them with the two from April to create an attack chain that could lead to a full system compromise.
Federal agencies have been told to assess how many vulnerable VMware products they have running on their network and either apply VMware’s patches, or remove all the products until they can be patched.
Agencies have also been told that if they had vulnerable products exposed to the internet that they should assume these have already been compromised and begin active threat hunting, reporting any abnormalities to CISA.
RELATED RESOURCE
Recommendations for managing AI risks
Integrate your external AI tool findings into your broader security programs
Agencies can reconnect products only if they found no anomalies and all the necessary updates have been applied.
CISA’s 2021 binding operational directive that mandated its growing list of known vulnerabilities that must be patched by federal agencies also applies for both CVE-2022-22954 and CVE-2022-22960.
The two flaws were added to the list of must-patch security issues in April; patching them is compulsory for all departments tasked with safeguarding federal information and information systems.
An earlier 2019 operational directive (19-02) also applies to this case, one that compelled the same federal and government agencies to ensure cyber hygiene is addressed in internet-facing systems.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
Security experts weigh in on motivation behind Stryker cyber attackNews The attack on medical tech company Stryker has severely impacted operations globally
-
The rise of PhaaS: what businesses should knowIn-depth With phishing as a service (PhaaS) on the rise, which new kits should firms know about and how can leaders avoid being caught out?
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities
-
Everything you need to know about Google and Apple’s emergency zero-day patchesNews A serious zero-day bug was spotted in Chrome systems that impacts Apple users too, forcing both companies to issue emergency patches