HomeSecurityCISA: SolarWinds, Ivanti and Workspace One vulnerabilities on the KEV list

CISA: SolarWinds, Ivanti and Workspace One vulnerabilities on KEV list

The United States Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) list, confirming that these vulnerabilities are already being exploited in real-world cyberattacks. The additions relate to SolarWinds, Ivanti, and Omnissa Workspace One.

CISA Vulnerabilities SolarWinds, Ivanti KEV

The KEV list is considered one of the most important early warning tools for organizations and government agencies, as it includes vulnerabilities that are not just theoretical but are already being used in attacks. The inclusion of a vulnerability on the list is a clear signal that be applied immediately patches security.

The three new vulnerabilities that were identified

The three vulnerabilities recently added to the KEV list concern well-known enterprise IT systems and infrastructure management tools. The first is CVE-2021-22054, with a CVSS severity rating of 7.5. This is a Server-Side Request Forgery (SSRF) vulnerability in Omnissa Workspace One UEM, formerly known as VMware Workspace One UEM . This vulnerability could allow an attacker with network access to send unauthenticated requests to the server and gain access to sensitive system.

See also: CISA adds SolarWinds WHD vulnerability to KEV List

The second vulnerability, CVE-2025-26399, is rated as extremely critical with a CVSS score of 9.8. It is located in the AjaxProxy component of SolarWinds Web Help Desk. Through this technique, an attacker can execute arbitrary commands on the central server, thereby gaining complete control of the system.

The third vulnerability, CVE-2026-1603, affects Ivanti Endpoint Manager and has a CVSS score of 8.6. It is an authentication bypass via an alternate path or channel, which could allow unauthorized remote attackers to gain access to stored user credentials.

Connection to ransomware attacks

The addition of CVE-2025-26399 to the KEV list was no coincidence. According to reports from Microsoft and cybersecurity firm Huntress, groups of attackers are exploiting this vulnerability to gain initial access to corporate networks.

CISA: SolarWinds, Ivanti and Workspace One vulnerabilities on KEV list

This activity is attributed to the group Warlock ransomware, which appears to be using the SolarWinds Web Help Desk vulnerability as an entry point before moving further into the network. Such attacks often follow a double blackmail model, where attackers not only encrypt an organization's data but also threaten to make it public.

Coordinated SSRF exploitation campaigns

Regarding the CVE-2021-22054 vulnerability, GreyNoise had already warned in March 2025 that it was being used in conjunction with other SSRF vulnerabilities in different products. These attacks appear to be part of a broader campaign to scan and exploit vulnerable systems on the internet.

See also: CISA warns of vulnerabilities in SolarWinds, Notepad++, Microsoft

SSRF attacks are particularly dangerous, as they allow an attacker to use an organization’s own server to send requests to internal systems that would normally not be accessible from the internet. In this way, security mechanisms can be bypassed and critical data can be exposed.

For the third vulnerability, CVE-2026-1603 in Ivanti Endpoint Manager, no details have yet been released on how it was exploited. At the time of this announcement, Ivanti's security bulletin had not been updated to officially confirm the active exploit.

Deadlines for applying security updates

CISA has given clear instructions to federal agencies (FCEBs) to immediately implement patch updates. Specifically, organizations must install the patch for SolarWinds Web Help Desk by March 12, 2026.

For the vulnerabilities affecting Omnissa Workspace One UEM and Ivanti Endpoint Manager, the deadline is set for March 23, 2026.These dates are considered critical, as attacks exploiting these vulnerabilities are already underway.

CISA: SolarWinds, Ivanti and Workspace One vulnerabilities on KEV list

Why the KEV list is considered a critical cybersecurity tool

The CISA Known Exploited Vulnerabilities list serves as a dynamic guide for organizations that want to prioritize their security patches. In an environment where thousands of new vulnerabilities are discovered each year, the ability to identify those already being used in attacks is extremely important.

See also: SolarWinds Serv-U: Critical vulnerabilities allow root access

CISA highlights that such vulnerabilities are one of the most common ways attackers gain access to systems. For this reason, rapid patching and continuous monitoring of systems are key defense measures for public and private sector organizations.

As cyber attacks become increasingly targeted and technically sophisticated, timely response to such warnings can make the difference between a preventive security measure and a serious data breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS