CVE-2026-22719
Sfruttamento noto · CISA KEV
CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 18% (97º percentile).
Data di correzione federale CISA 24 mar
Vulnerabilità · 209 giorni fa
CISA added CVE-2026-22719 — a VMware Aria Operations command injection reported exploited in the wild — to its Known Exploited Vulnerabilities catalog. Broadcom released fixes: Aria Operations 8.18.6 and VMware Cloud Foundation / vSphere Foundation 9.0.2.0; it also patched CVE-2026-22720 (stored cross-site scripting) and CVE-2026-22721 (privilege escalation). Patch immediately; if you cannot patch within 48 hours run Broadcom’s aria-ops-rce-workaround.sh as root on each Aria Operations appliance node and verify patch application. FCEB deadline: March 24, 2026.
Sfruttamento noto · CISA KEV
CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 18% (97º percentile).
Data di correzione federale CISA 24 mar
CVSS 6.2 MEDIUM: vMware Aria Operations contains a privilege escalation vulnerability. EPSS 0.7% (52º percentile).
CVSS 8 HIGH: vMware Aria Operations contains a stored cross-site scripting vulnerability. EPSS 0.4% (33º percentile).
3 fonti che coprono questa storia
VMware Aria Operations Bug Exploited, Cloud Resources at Risk
Exploitation of the command injection flaw in VMware Aria Operations could grant an attacker broad acess to victims' cloud environments.
VMware Aria Operations Vulnerability Exploited in the Wild
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.
CISA flags VMware Aria Operations RCE flaw as exploited in attacks
Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks.
Part of the PlainSec briefing for 2026-03-07