logo

VMware Aria Operations Bug Exploited, Cloud Resources at Risk

ID: 075a334b-2c8a-5606-bf3c-eee5bf4333b5

STIX ID: report--075a334b-2c8a-5606-bf3c-eee5bf4333b5

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

CVE-2026-22719 is a high-severity (CVSS 8.1) unauthenticated command-injection flaw in VMware Aria Operations (affecting Aria 8 up to 8.18.5 and Aria 9 up to 9.0.1) that can lead to root remote code execution during support-assisted migrations; CISA added it to its Known Exploited Vulnerabilities catalog and Broadcom published patches (8.18.6 / VCF 9.0.2.0) and a workaround script, with the report warning that compromise of Aria Operations can expose credentials, topology, and enable large-scale intrusions across virtual estates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.