CISA Confirms Active Exploitation of VMware Aria Operations Vulnerability
Mar 4, 2026 // 08:18 - Lina Schonbein


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity VMware Aria Operations vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog as of March 3, 2026. 

Vulnerability Profile

  • CVE ID: CVE-2026-22719
  • CVSS Score: 8.1 (Important)
  • Type: Command Injection / Remote Code Execution (RCE)
  • The Flaw: An unauthenticated attacker can execute arbitrary commands on the underlying system, potentially leading to full remote code execution. This occurs specifically during support-assisted product migration. 

Exploitation and Risk

  • Active Attacks: While Broadcom (VMware’s parent company) originally disclosed the flaw on February 24, it later updated its advisory to confirm reports of potential exploitation in the wild.
  • Attack Complexity: The attack window is limited to when a migration is actively in progress, but the lack of required authentication makes it highly dangerous if timed correctly.
  • Other Related Flaws: This RCE was patched alongside two other vulnerabilities:
    • CVE-2026-22720: Stored XSS (CVSS 8.0) allowing administrative session hijacking.
    • CVE-2026-22721: Privilege escalation to root (CVSS 6.2). 

Required Actions

  • Patch Immediately: Administrators should update to Aria Operations 8.18.6 or VMware Cloud/vSphere Foundation 9.0.2.0.
  • Federal Deadline: CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies remediate this vulnerability by March 24, 2026.
  • Workaround: If immediate patching is not possible, VMware has provided a remediation script to mitigate the RCE risk.

#active  #aria  #cisa  #confirms  #exploitation  #news  #operations  #vmware  #vulnerability   —   News