VMware Aria Operations Bug Exploited, Cloud Resources at Risk
ID: 075a334b-2c8a-5606-bf3c-eee5bf4333b5
STIX ID: report--075a334b-2c8a-5606-bf3c-eee5bf4333b5
Feed Name: Dark Reading
CVE-2026-22719 is a high-severity (CVSS 8.1) unauthenticated command-injection flaw in VMware Aria Operations (affecting Aria 8 up to 8.18.5 and Aria 9 up to 9.0.1) that can lead to root remote code execution during support-assisted migrations; CISA added it to its Known Exploited Vulnerabilities catalog and Broadcom published patches (8.18.6 / VCF 9.0.2.0) and a workaround script, with the report warning that compromise of Aria Operations can expose credentials, topology, and enable large-scale intrusions across virtual estates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
