logo

CISA flags VMware Aria Operations RCE flaw as exploited in attacks

ID: 03702e11-14ff-5dd1-b665-f8beadac418e

STIX ID: report--03702e11-14ff-5dd1-b665-f8beadac418e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

CVE-2026-22719 is a command injection vulnerability in VMware Aria Operations (CVSS 8.1) patched by Broadcom (VMSA-2026-0001) and added to CISA's Known Exploited Vulnerabilities catalog; an unauthenticated attacker could execute arbitrary commands leading to RCE during migration. Broadcom published fixes and a root-run workaround script to disable migration components, and while there are reports of in-the-wild exploitation the vendor says it cannot independently confirm those reports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.