Skip to content
VulniPulse

Omnissa (ex-VMware EUC) Security Advisories & CVEs

6 advisories tracked · Omnissa Security Advisories (OMSA) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Omnissa CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Omnissa device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Omnissa's recent advisories.

Official source

Omnissa Security Advisories (OMSA)

Omnissa (the former VMware End-User Computing division: Workspace ONE and Horizon) is its own CVE Numbering Authority. VulniPulse ingests Omnissa's CVEs from the NVD CNA feed, grouped by the official OMSA-YYYY-NNNN advisory each CVE references, then enriches severity, CVSS and impacted products from the official Omnissa Security Response index. Covers Workspace ONE UEM, Intelligent Hub, Access, Tunnel and Assist, Horizon 8 / Horizon Client, App Volumes and Unified Access Gateway (UAG) — UAG and Horizon are internet-facing and historically heavily probed.

Latest Omnissa advisories

High7.8Omnissa

High [CVE-2026-22927] Omnissa Workspace ONE Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.

CVE-2026-22927
Workspace ONE Apps (Hub/Tunnel/Assist)
Jul 8, 2026
High7.8Omnissa

High [CVE-2026-22926] Omnissa Workspace ONE Assist for macOS contains a Local Privilege Escalation Vulnerability.

Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

CVE-2026-22926
Workspace ONE Apps (Hub/Tunnel/Assist)
Jun 9, 2026
High7.1Omnissa

High [CVE-2025-25234] UAG: Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability.

Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks. Affected product named by the advisory: Unified Access Gateway.

CVE-2025-25234
Unified Access Gateway
Apr 17, 2025
High7.8Omnissa

High [CVE-2025-25230] Horizon Client: Omnissa Horizon Client for Windows contains an LPE Vulnerability.

Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.

CVE-2025-25230
Horizon
Apr 16, 2025
High7.8Omnissa

High [CVE-2024-11468] Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.

CVE-2024-11468
Horizon
Feb 4, 2025
High7.8Omnissa

High [CVE-2024-11467] Horizon Client: Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw.

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.

CVE-2024-11467
Horizon
Feb 4, 2025

← All vendors