VMware advises: “Patch Me Now!”

Share This Post

Ten vulnerabilities have recently been fixed in patches released by VMware. Products affected include:

VMware Workspace ONE Access (Access)
VMware Workspace ONE Access Connector (Access Connector)
VMware Identity Manager (vIDM)
VMware Identity Manager Connector (vIDM Connector)
VMware vRealize Automation (vRA)
VMware Cloud Foundation
vRealize Suite Lifecycle Manager

One of these vulnerabilities is CVE-2022-31656. While a severity rating has not been assigned to this vulnerability at the time of this writing, it is believed (based on early reports) that this is a variant or patch bypass of CVE-2022-22972, which was patched in May of 2022 and carried a severity rating of 7.5 out of 10.
Petrus Viet, the researcher who discovered this vulnerability, has also reported CVE-2022-31659, a SQL injection flaw that can be exploited to trigger a remote code execution. Some combination of these recent vulnerabilities, which include an authentication bypass and remote code execution, could make for some very nasty and troublesome exploit chains. Patching these vulnerabilities should be at the top of every VMWare administrator’s to-do list.

For the full advisory from VMware, please visit: https://www.vmware.com/security/advisories/VMSA-2022-0021.html



Reach out to our incident response team for help

More To Explore

Information Security News – 6/15/26

Oracle PeopleSoft Servers Hacked in ShinyHunters Data Theft Attacks Article Link: https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/ Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code Article Link: https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html

Information Security News – 6/8/26

CISA Warns of Active Attacks Exploiting Android, Linux Bugs Article Link: https://www.bleepingcomputer.com/news/security/cisa-warns-of-active-attacks-exploiting-android-linux-bugs/ Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT Article Link:

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.