Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

VMware Aria Operations Vulnerability Exploited in the Wild

The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution. 

VMware

A recently patched vulnerability in VMware Aria Operations (formerly vRealize Operations) has been exploited in the wild, the cybersecurity agency CISA warned on Tuesday.

The vulnerability, tracked as CVE-2026-22719, is a high-severity command injection issue that can be exploited without authentication.

“A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress,” Broadcom explained in a February 24 advisory announcing patches for the flaw.

CISA added CVE-2026-22719 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, instructing federal agencies to address it by March 24.

There appears to be no public information describing attacks involving the vulnerability. 

In an update to its initial advisory, Broadcom noted, “Broadcom is aware of reports of potential exploitation of CVE-2026-22719 in the wild, but we cannot independently confirm their validity”.

Advertisement. Scroll to continue reading.

It’s unclear whether Broadcom learned about the in-the-wild exploitation from CISA or a different source.

It’s also unclear whether exploitation of the vulnerability started after a patch was released or CVE-2026-22719 was exploited as a zero-day. 

Nevertheless, it’s encouraging to see Broadcom promptly update its security advisory when potential exploitation of a vulnerability is detected. In contrast, the company has previously faced criticism for delaying such warnings even when exploitation was known for extended periods.

Related: Scattered Spider Targeting VMware vSphere Environments

Related: 2024 VMware Flaw Now in Attackers’ Crosshairs

Related: Exploit for VMware Zero-Day Flaws Likely Built a Year Before Public Disclosure

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Rapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.