ZeroHour

CVE-2026-22719

KEVlarge

Unauthenticated Command Injection RCE in Broadcom VMware Aria Operations

CISA: Broadcom VMware Aria Operations Command Injection Vulnerability

CVSS 3.1
8.1 high
EPSS
17%p97
Published
()
KEV added
AI analysis

Broadcom's VMware Aria Operations (formerly vRealize Operations) contains a command injection flaw (CWE-77, CVSS 3.1 base score 8.1) that allows a malicious unauthenticated remote actor to execute arbitrary operating-system commands. The vulnerability is only exploitable while a support-assisted product migration is in progress, which narrows the attack window but requires no privileges or user interaction. Successful exploitation yields remote code execution on the affected Aria Operations instance. Organizations running Aria Operations standalone or as part of VMware Cloud Foundation, VMware Telco Cloud Infrastructure, or VMware Telco Cloud Platform are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-03, and its EPSS score of 17.4% (97th percentile) indicates elevated near-term exploitation risk.

What to do: Apply the patches listed in the Fixed Version column of the Response Matrix in VMSA-2026-0001 (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947). If patching must be delayed, implement the workarounds documented in the Workarounds column of the same Response Matrix and defer any support-assisted product migrations until systems are patched. Federal agencies must follow BOD 22-01 guidance given the KEV listing; all defenders should check whether support-assisted migrations are in progress or scheduled on their Aria Operations instances.

Affected
Broadcom (VMware) VMware Aria Operations
Broadcom (VMware) VMware Cloud Foundation (with Aria Operations)
Broadcom (VMware) VMware Telco Cloud Infrastructure (with Aria Operations)
Broadcom (VMware) VMware Telco Cloud Platform (with Aria Operations)
Estimated exposure
large≈10,000–100,000 enterprise deployments of Aria Operations worldwide, with only instances running a support-assisted migration exploitable at any given time — Aria Operations is a widely deployed private-cloud monitoring product bundled with VMware Cloud Foundation and Telco Cloud offerings across tens of thousands of enterprise environments, while public internet scans have historically shown…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

CISA Known Exploited Vulnerability
Affected
Broadcom VMware Aria Operations
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
aria operations, cloud foundation, telco cloud infrastructure, telco cloud platform
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

CISA warns ransomware gangs now exploit critical VMware vCenter syslog RCE CVE-2026-59310, already KEV-listed after APT compromises across 47 countries.

Broadcom patched critical directory traversal flaw CVE-2026-59310 in the vCenter Syslog server on July 29, warning of unauthenticated remote code execution. QUIRSO subsequently found 361 compromised IPs across 47 countries after a suspected APT deployed a reverse SSH tool for persistence and remote access. CISA added the flaw to its KEV catalog with a three-day patch deadline for federal agencies, and over the weekend updated it to flag active abuse by ransomware gangs. Shadowserver tracks over 450 exposed vCenter servers, and CISA has tagged 26 VMware vulnerabilities as exploited in the wild over five years, nine abused by ransomware.