CVE-2026-22719
Known exploited · CISA KEV
CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 17% (97th percentile).
CISA federal remediation date Mar 24
Vulnerabilities & Exploits · Zero-Day Exploit
CISA added CVE-2026-22719—a command injection in VMware Aria Operations—to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Broadcom released patches and a temporary workaround; federal civilian agencies must remediate by March 24, 2026.
3 sources · Mar 4
Known exploited · CISA KEV
CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 17% (97th percentile).
CISA federal remediation date Mar 24
CVSS 6.2 MEDIUM: vMware Aria Operations contains a privilege escalation vulnerability. EPSS 0.7% (48th percentile), up from 0.03%.
CVSS 8 HIGH: vMware Aria Operations contains a stored cross-site scripting vulnerability. EPSS 0.4% (33rd percentile).
Dark Reading
VMware Aria Operations Bug Exploited, Cloud Resources at Risk
Exploitation of the command injection flaw in VMware Aria Operations could grant an attacker broad acess to victims' cloud environments.
originalSecurityWeek
VMware Aria Operations Vulnerability Exploited in the Wild
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.
originalBleepingComputer
CISA flags VMware Aria Operations RCE flaw as exploited in attacks
Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks.
originalPart of the PlainSec briefing for 2026-03-05
Every edition of this story: CISA Adds VMware Aria Operations Flaw to KEV