CVE-2026-22719
Known exploited · CISA KEV
CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 17% (97th percentile).
CISA federal remediation date Mar 24
Vulnerabilities · 195 days ago
CISA added CVE-2026-22719 — a VMware Aria Operations command injection reported exploited in the wild — to its Known Exploited Vulnerabilities catalog. Broadcom released fixes: Aria Operations 8.18.6 and VMware Cloud Foundation / vSphere Foundation 9.0.2.0; it also patched CVE-2026-22720 (stored cross-site scripting) and CVE-2026-22721 (privilege escalation). Patch immediately; if you cannot patch within 48 hours run Broadcom’s aria-ops-rce-workaround.sh as root on each Aria Operations appliance node and verify patch application. FCEB deadline: March 24, 2026.
Known exploited · CISA KEV
CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 17% (97th percentile).
CISA federal remediation date Mar 24
CVSS 6.2 MEDIUM: vMware Aria Operations contains a privilege escalation vulnerability. EPSS 0.7% (48th percentile), up from 0.03%.
CVSS 8 HIGH: vMware Aria Operations contains a stored cross-site scripting vulnerability. EPSS 0.4% (33rd percentile).
3 sources covering this story
VMware Aria Operations Bug Exploited, Cloud Resources at Risk
Exploitation of the command injection flaw in VMware Aria Operations could grant an attacker broad acess to victims' cloud environments.
VMware Aria Operations Vulnerability Exploited in the Wild
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.
CISA flags VMware Aria Operations RCE flaw as exploited in attacks
Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks.
Part of the PlainSec briefing for 2026-03-07