Omnissa, LLC
First CVE: Feb 4, 2025Active for: 1 year
10
CVEs Published
More CVEs Published than 27% of tracked CNAs
5.0
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 60% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Omnissa, LLC as a CNA, 20.0% affect products that Omnissa, LLC develops as a vendor.
20.0%
80.0%
Self-reported: 2Third-party: 8
Of all the CVEs published that affect products developed by Omnissa, LLC, 100.0% are self-published by Omnissa, LLC as a CNA.
100.0%
Self-published: 2Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by Omnissa, LLC over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 4, 2025
17 months ago
Most Recent CVE
Jul 8, 2026
16 days ago
Top CVEs
All CVEs published by Omnissa, LLC as a CNA, regardless of affected vendor or product.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25231HIGH Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET re | Aug 11, 2025 | 7.5 | 53 | NO | YES |
CVE-2026-22927HIGH Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. | Jul 8, 2026 | 7.8 | 34 | NO | NO |
CVE-2026-22926HIGH Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | Jun 9, 2026 | 7.8 | 31 | NO | NO |
CVE-2025-25235HIGH Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2.32 running on Windows and SEG prior to 2503 running on UAG allows routing of network traf | Aug 11, 2025 | 8.6 | 28 | NO | NO |
CVE-2025-25230HIGH Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privilege | Apr 16, 2025 | 7.8 | 23 | NO | NO |
CVE-2024-11468HIGH Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allo | Feb 4, 2025 | 7.8 | 22 | NO | NO |
CVE-2024-11467HIGH Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user | Feb 4, 2025 | 7.8 | 22 | NO | NO |
CVE-2025-25229MEDIUM Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability. A malicious actor with user privileges may be able to access restricted internal system infor | Aug 11, 2025 | 5.4 | 21 | NO | NO |
CVE-2025-25234HIGH Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS r | Apr 17, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-25236MEDIUM Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to enumerate sensitive information such as tenant ID and user acc | Nov 12, 2025 | 5.3 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA10 CVEs
20%
80%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (50.0%)
Network5 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None4 (40.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Omnissa, LLC as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Omnissa, LLC as a CNA — matched by CVE ID, not by organization name.