CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Monday that it has placed three software flaws onto its Known Exploited Vulnerabilities (KEV) list after investigators found evidence these weaknesses are being used in the wild.
The issues added to the KEV inventory are as follows:
CVE-2021-22054 (CVSS 7.5) – An SSRF (server-side request forgery) bug in Omnissa Workspace One UEM (previously VMware Workspace One UEM). An attacker with network reachability to the UEM could exploit this flaw to issue unauthenticated requests and potentially retrieve sensitive information.
CVE-2025-26399 (CVSS 9.8) – A vulnerability stemming from deserialization of untrusted data in the AjaxProxy component of SolarWinds Web Help Desk. If exploited, this flaw can permit an attacker to execute commands on the underlying host.
CVE-2026-1603 (CVSS 8.6) – An authentication bypass via an alternate path or channel in Ivanti Endpoint Manager. This weakness could allow a remote, unauthenticated actor to expose certain stored credential data.
Microsoft and Huntress have reported that attackers are leveraging flaws in SolarWinds Web Help Desk to gain initial footholds, and those intrusions are attributed to the Warlock ransomware group.
GreyNoise observed exploitation of CVE-2021-22054 in March 2025, noting it was used alongside other SSRF vulnerabilities across multiple products as part of a coordinated campaign.
At this time there is no public technical detail indicating how CVE-2026-1603 is being operationalized by attackers. Ivanti has not yet updated its security advisory to reflect active exploitation of the issue.
To reduce the risk to federal systems, CISA has ordered Federal Civilian Executive Branch (FCEB) agencies to remediate the SolarWinds Web Help Desk vulnerability (CVE-2025-26399) by March 12, 2026. The fixes for the other two defects (CVE-2021-22054 and CVE-2026-1603) must be applied by March 23, 2026.
CISA emphasized that these categories of flaws are commonly abused by threat actors and represent considerable danger to the federal enterprise, urging organizations to prioritize remediation.