Vulnerabilities & Exploits · Zero-Day Exploit

CISA Adds VMware Aria Operations Flaw to KEV

CISA added CVE-2026-22719—a command injection in VMware Aria Operations—to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Broadcom released patches and a temporary workaround; federal civilian agencies must remediate by March 24, 2026.

3 sources · Mar 4

CVE-2026-22719

NVD KEV

Known exploited · CISA KEV

CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 17% (97th percentile).

CISA federal remediation date Mar 24

CVE-2026-22721

NVD KEV

CVSS 6.2 MEDIUM: vMware Aria Operations contains a privilege escalation vulnerability. EPSS 0.7% (48th percentile), up from 0.03%.

CVE-2026-22720

NVD KEV

CVSS 8 HIGH: vMware Aria Operations contains a stored cross-site scripting vulnerability. EPSS 0.4% (33rd percentile).

Timeline

Sources

Vendor digest: VMware

Part of the PlainSec briefing for 2026-03-04

Every edition of this story: CISA Adds VMware Aria Operations Flaw to KEV

More from today