Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence

VMware Workspace ONE Flaw CVE-2022-22954 Hit by Active Malware Campaigns

Updated 29d agoFirst seen May 25, 20262 sources

Attackers actively exploited VMware Workspace ONE Access, Identity Manager, and vRealize Automation flaws in the wild, with CVE-2022-22954 emerging as the primary initial access vector. Palo Alto Networks Unit 42 said exploitation began shortly after VMware disclosed the issue, describing the bug as a trivial server-side template injection that can be triggered with a single HTTP request for remote code execution. The activity prompted a CISA alert, and researchers warned that related VMware flaws CVE-2022-22972 and CVE-2022-22973 were also highly likely to be targeted.

Observed post-exploitation activity included deployment of Mirai and Gafgyt variants, Enemybot, webshells, Perl-based shellbots, coinminers, and payloads that modified SSH keys for persistence. Unit 42 reported that attackers could chain CVE-2022-22960 after the initial compromise to escalate privileges to root by abusing writable paths and sudo-accessible scripts. The company said its Threat Prevention signature 92483 blocks exploitation attempts and noted that about 800 internet-exposed Workspace ONE Access instances were visible, underscoring the exposure risk for unpatched organizations.

Share:
VMware Workspace ONE Flaw CVE-2022-22954 Hit by Active Malware Campaigns
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 20, 20224y ago

Unit 42 publishes technical analysis and IOCs for VMware attacks

Palo Alto Networks Unit 42 published a threat brief documenting widespread exploitation, attack chains involving CVE-2022-22954 and CVE-2022-22960, and indicators of compromise such as malware URLs, hashes, and command-and-control details. The report also noted roughly 800 internet-exposed Workspace ONE Access instances identified by Cortex Xpanse.

May 18, 20224y ago

CISA issues alert on active VMware exploitation

CISA issued an alert warning about active exploitation of VMware vulnerabilities, including CVE-2022-22954. The alert reflected growing official concern over ongoing attacks against exposed systems.

VMware discloses additional flaws including CVE-2022-22960

In May 2022, VMware disclosed additional vulnerabilities including CVE-2022-22960, which could be used after CVE-2022-22954 for privilege escalation to root. Unit 42 assessed CVE-2022-22972 and CVE-2022-22973 as also highly likely to be exploited.

Apr 11, 20224y ago

Attackers begin exploiting CVE-2022-22954 in the wild

Unit 42 observed exploitation attempts for CVE-2022-22954 starting on April 11, 2022. Attackers used the flaw to deploy Mirai and Gafgyt variants, Enemybot, webshells, shellbots, coinminers, and SSH key manipulation payloads.

Apr 6, 20224y ago

VMware discloses Workspace ONE Access and related vulnerabilities

VMware published an advisory covering vulnerabilities affecting Workspace ONE Access, Identity Manager, and related products, including CVE-2022-22954. This disclosure preceded observed exploitation activity by only a few days.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.