CISA flags VMware Aria Operations RCE flaw as exploited in attacks
ID: 03702e11-14ff-5dd1-b665-f8beadac418e
STIX ID: report--03702e11-14ff-5dd1-b665-f8beadac418e
Feed Name: Bleeping Computer
CVE-2026-22719 is a command injection vulnerability in VMware Aria Operations (CVSS 8.1) patched by Broadcom (VMSA-2026-0001) and added to CISA's Known Exploited Vulnerabilities catalog; an unauthenticated attacker could execute arbitrary commands leading to RCE during migration. Broadcom published fixes and a root-run workaround script to disable migration components, and while there are reports of in-the-wild exploitation the vendor says it cannot independently confirm those reports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
