Vulnerabilities · 195 days ago

CISA Adds Aria Operations Command Injection (CVE-2026-22719) to KEV

CISA added CVE-2026-22719 — a VMware Aria Operations command injection reported exploited in the wild — to its Known Exploited Vulnerabilities catalog. Broadcom released fixes: Aria Operations 8.18.6 and VMware Cloud Foundation / vSphere Foundation 9.0.2.0; it also patched CVE-2026-22720 (stored cross-site scripting) and CVE-2026-22721 (privilege escalation). Patch immediately; if you cannot patch within 48 hours run Broadcom’s aria-ops-rce-workaround.sh as root on each Aria Operations appliance node and verify patch application. FCEB deadline: March 24, 2026.

CVE-2026-22719

NVD KEV

Known exploited · CISA KEV

CVSS 8.1 HIGH: vMware Aria Operations contains a command injection vulnerability. EPSS 17% (97th percentile).

CISA federal remediation date Mar 24

CVE-2026-22721

NVD KEV

CVSS 6.2 MEDIUM: vMware Aria Operations contains a privilege escalation vulnerability. EPSS 0.7% (48th percentile), up from 0.03%.

CVE-2026-22720

NVD KEV

CVSS 8 HIGH: vMware Aria Operations contains a stored cross-site scripting vulnerability. EPSS 0.4% (33rd percentile).

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: VMware

Part of the PlainSec briefing for 2026-03-07

Editions

Related stories