Broadcom's VMware Aria Operations (formerly vRealize Operations) contains a command injection flaw (CWE-77, CVSS 3.1 base score 8.1) that allows a malicious unauthenticated remote actor to execute arbitrary operating-system commands. The vulnerability is only exploitable while a support-assisted product migration is in progress, which narrows the attack window but requires no privileges or user interaction. Successful exploitation yields remote code execution on the affected Aria Operations instance. Organizations running Aria Operations standalone or as part of VMware Cloud Foundation, VMware Telco Cloud Infrastructure, or VMware Telco Cloud Platform are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-03, and its EPSS score of 17.4% (97th percentile) indicates elevated near-term exploitation risk.
What to do: Apply the patches listed in the Fixed Version column of the Response Matrix in VMSA-2026-0001 (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947). If patching must be delayed, implement the workarounds documented in the Workarounds column of the same Response Matrix and defer any support-assisted product migrations until systems are patched. Federal agencies must follow BOD 22-01 guidance given the KEV listing; all defenders should check whether support-assisted migrations are in progress or scheduled on their Aria Operations instances.
Affected
Broadcom (VMware) VMware Aria Operations
—
Broadcom (VMware) VMware Cloud Foundation (with Aria Operations)
large≈10,000–100,000 enterprise deployments of Aria Operations worldwide, with only instances running a support-assisted migration exploitable at any given time — Aria Operations is a widely deployed private-cloud monitoring product bundled with VMware Cloud Foundation and Telco Cloud offerings across tens of thousands of enterprise environments, while public internet scans have historically shown…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
CISA Known Exploited Vulnerability
Affected
Broadcom VMware Aria Operations
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA warns ransomware gangs now exploit critical VMware vCenter syslog RCE CVE-2026-59310, already KEV-listed after APT compromises across 47 countries.
Broadcom patched critical directory traversal flaw CVE-2026-59310 in the vCenter Syslog server on July 29, warning of unauthenticated remote code execution. QUIRSO subsequently found 361 compromised IPs across 47 countries after a suspected APT deployed a reverse SSH tool for persistence and remote access. CISA added the flaw to its KEV catalog with a three-day patch deadline for federal agencies, and over the weekend updated it to flag active abuse by ransomware gangs. Shadowserver tracks over 450 exposed vCenter servers, and CISA has tagged 26 VMware vulnerabilities as exploited in the wild over five years, nine abused by ransomware.