CISA Warns of Software Product Vulnerabilities; Director Jen Easterly Quoted

The Cybersecurity and Infrastructure Security Agency has released an emergency directive asking federal civilian agencies to apply updates or remove certain VMware products from their networks to help mitigate potential vulnerabilities in such products.

CISA issued the directive after it found that a series of four vulnerabilities in several VMware products were being exploited by malicious cyber actors, the agency said Wednesday.

These impacted VMware products include VMware Workspace ONE Access, VMware Cloud Foundation, VMware Identity Manager, VMware vRealize Automation and vRealize Suite Lifecycle Manager.

According to the emergency directive, all federal civilian agencies should enumerate all instances of impacted VMware products on agency networks and deploy updates or remove them until updates are implemented by May 23.

By May 24, agencies should report the status of all instances outlined in the directive’s first required action.

These vulnerabilities pose an unacceptable risk to federal network security,” said CISA Director Jen Easterly, a 2022 Wash100 Award winner.

CISA has issued this Emergency Directive to ensure that federal civilian agencies take urgent action to protect their networks. We also strongly urge every organization – large and small – to follow the federal government’s lead and take similar steps to safeguard their networks,” added Easterly.

Share the Post:

Related Posts

Key Takeaways From Baird’s 2025 Defense & Government Conference

Co-authored with Pat Host For eight years, investment banking firm Baird has brought the government contracting community a sterling conference every November to take the pulse on the industry’s current...

Saluting First-Time 2025 Wash100 Winners From Government

The annual Wash100 Award represents the apex of an executive’s career. Issued by Executive Mosaic, the GovCon industry’s leading events, media and membership organization, the first-time winners from the class...

The Five Foundational Values of the Wash100 Award

The Wash100 Award is the ultimate achievement in a GovCon executive’s career. The award, created by Executive Mosaic in 2014, is the yearly recognition of GovCon leaders who demonstrate excellence...