ZeroHour
Security Affairspublished ()ingested @securityaffairs

VMware Aria Operations flaws could enable remote attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22719
Unauthenticated Command Injection RCE in Broadcom VMware Aria Operations

Broadcom's VMware Aria Operations (formerly vRealize Operations) contains a command injection flaw (CWE-77, CVSS 3.1 base score 8.1) that allows a malicious unauthenticated remote actor to execute arbitrary operating-system commands. The vulnerability is only exploitable while a support-assisted product migration is in progress, which narrows the attack window but requires no privileges or user interaction. Successful exploitation yields remote code execution on the affected Aria Operations instance. Organizations running Aria Operations standalone or as part of VMware Cloud Foundation, VMware Telco Cloud Infrastructure, or VMware Telco Cloud Platform are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-03, and its EPSS score of 17.4% (97th percentile) indicates elevated near-term exploitation risk.

Do: Apply the patches listed in the Fixed Version column of the Response Matrix in VMSA-2026-0001 (https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947). If patching must be delayed, implement the workarounds documented in the Workarounds column of the same Response Matrix and defer any support-assisted product migrations until systems are patched. Federal agencies must follow BOD 22-01 guidance given the KEV listing; all defenders should check whether support-assisted migrations are in progress or scheduled on their Aria Operations instances.

8.117% KEV
  • Broadcom (VMware) VMware Aria Operations
  • Broadcom (VMware) VMware Cloud Foundation (with Aria Operations)
  • Broadcom (VMware) VMware Telco Cloud Infrastructure (with Aria Operations)
  • +1 more
large≈10,000–100,000 enterprise deployments of Aria Operations worldwide, with only instances running a support-assisted migration exploitable at any given time
CVE-2026-22720
+1 in the same advisory: …22721
VMware Aria Operations contains a stored cross-site scripting vulnerability.

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations. To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .

NVD description · AI analysis pending
9.0
group max
<1%
  • vmware aria operations
  • vmware cloud foundation
  • vmware telco cloud infrastructure
  • +1 more
Full article297 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 24, 2026

Broadcom patched multiple VMware Aria Operations flaws, including high-severity issues that could enable remote code execution.

Broadcom has released security updates to address multiple vulnerabilities affecting VMware Aria Operations.

VMware Aria Operations is an IT operations management platform that helps organizations monitor and optimize virtual, cloud, and hybrid environments. It provides performance monitoring, capacity planning, automated alerting, and cost analysis, giving IT teams greater visibility and control over infrastructure to ensure efficiency, reliability, and compliance.

The most severe of the flaws is a command injection vulnerability, tracked as CVE-2026-22719 (CVSS 8.1), which an unauthenticated attacker can exploit remotely.

“A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.” reads the advisory.

This vulnerability was privately reported to Broadcom.

The company also addressed a high-severity stored cross-site scripting (XSS) flaw in Aria Operations. The vulnerability, tracked as CVE-2026-22720 (CVSS score of 8.0), is a stored cross-site scripting (XSS).

A threat actor with privileges to create custom benchmarks can exploit the flaw to inject script to perform administrative actions in VMware Aria Operations.

The third vulnerability addressed by Broadcom is a medium-severity privilege escalation issue, tracked as CVE-2026-22721 (CVSS score of 6.2) that can be exploited to obtain administrative access.

VMware Cloud Foundation (v9.0.2.0), VMware vSphere Foundation (v9.0.2.0), and Aria Operations (v8.18.6) address the above issues. Customers are strongly urged to apply these updates promptly to protect systems, minimize the risk of compromise, and reduce exposure to potential attacks.

The company did not say if any of these flaws was exploited in attacks in the wild.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Broadcom)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/188445/security/vmware-aria-operations-flaws-could-enable-remote-attacks.html