CISA's list that day
9 March 2026
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Omnissa Workspace One UEM, SolarWinds Web Help Desk and Ivanti Endpoint Manager (EPM). The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-26399Deserialization of Untrusted Data | SolarWinds Web Help Desk | Patch nowRansomware use, listed within a year | 0.90 | ||
| CVE-2021-22054Workspace ONE Server-Side Request Forgery | Omnissa Workspace One UEM | Patch this weekEPSS 0.99 | 0.99 | ||
| CVE-2026-1603Authentication Bypass | Ivanti Endpoint Manager (EPM) | Patch this weekEPSS 0.88 | 0.88 |