CISA added CVE-2026-22719 — a VMware Aria Operations command injection reported exploited in the wild — to its Known Exploited Vulnerabilities catalog. Broadcom released fixes: Aria Operations 8.18.6 and VMware Cloud Foundation / vSphere Foundation 9.0.2.0; it also patched CVE-2026-22720 (stored cross-site scripting) and CVE-2026-22721 (privilege escalation). Patch immediately; if you cannot patch within 48 hours run Broadcom’s aria-ops-rce-workaround.sh as root on each Aria Operations appliance node and verify patch application. FCEB deadline: March 24, 2026.
Part of the PlainSec briefing for 2026-03-07