CVE-2025-25234: Omnissa Unified Access Gateway

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.

Affected products

  • Omnissa Unified Access Gateway: before 2503 (fixed in 2503)

Published 2025-04-17. Last modified 2026-06-17.