Omnissa (ex-VMware EUC) Security Advisories & CVEs
6 advisories tracked · Omnissa Security Advisories (OMSA) · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Omnissa CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Omnissa device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Omnissa's recent advisories.
Official source
Omnissa Security Advisories (OMSA)
Omnissa (the former VMware End-User Computing division: Workspace ONE and Horizon) is its own CVE Numbering Authority. VulniPulse ingests Omnissa's CVEs from the NVD CNA feed, grouped by the official OMSA-YYYY-NNNN advisory each CVE references, then enriches severity, CVSS and impacted products from the official Omnissa Security Response index. Covers Workspace ONE UEM, Intelligent Hub, Access, Tunnel and Assist, Horizon 8 / Horizon Client, App Volumes and Unified Access Gateway (UAG) — UAG and Horizon are internet-facing and historically heavily probed.
Latest Omnissa advisories
High [CVE-2026-22927] Omnissa Workspace ONE Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
High [CVE-2026-22926] Omnissa Workspace ONE Assist for macOS contains a Local Privilege Escalation Vulnerability.
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
High [CVE-2025-25234] UAG: Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability.
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks. Affected product named by the advisory: Unified Access Gateway.
High [CVE-2025-25230] Horizon Client: Omnissa Horizon Client for Windows contains an LPE Vulnerability.
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.
High [CVE-2024-11468] Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
High [CVE-2024-11467] Horizon Client: Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw.
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.