ED 22-03, Mitigate VMware Vulnerabilities
RetiredCISA · Emergency Directive · May 18, 2022
Summary
Required agencies to find all instances of affected VMware identity and automation products, then either install VMware's May 2022 updates or remove those instances from agency networks, and to check internet-facing instances for compromise.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Emergency Directive
- Number
- ED 22-03
- Issued
- May 18, 2022
- Status
- Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Retired by CISA on January 8, 2026, which found its required actions complete or covered by BOD 22-01.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.