Organizations federal and otherwise that have certain VMware products connected to the Internet should act as if they’ve been compromised, the Cybersecurity and Infrastructure Security Agency said in a May 18 alert.
U.S. Cybersecurity and Infrastructure Agency issues emergency security directive over VMware vulnerabilities CVE-2022-22972 and CVE-2022-22973, which threat actors are likely to exploit.