Vulnerabilities

VMware Aria Operations Vulnerability Exploited in the Wild

The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution. 

VMware

A recently patched vulnerability in VMware Aria Operations (formerly vRealize Operations) has been exploited in the wild, the cybersecurity agency CISA warned on Tuesday.

The vulnerability, tracked as CVE-2026-22719, is a high-severity command injection issue that can be exploited without authentication.

“A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress,” Broadcom explained in a February 24 advisory announcing patches for the flaw.

CISA added CVE-2026-22719 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, instructing federal agencies to address it by March 24.

There appears to be no public information describing attacks involving the vulnerability. 

In an update to its initial advisory, Broadcom noted, “Broadcom is aware of reports of potential exploitation of CVE-2026-22719 in the wild, but we cannot independently confirm their validity”.

Advertisement. Scroll to continue reading.

It’s unclear whether Broadcom learned about the in-the-wild exploitation from CISA or a different source.

It’s also unclear whether exploitation of the vulnerability started after a patch was released or CVE-2026-22719 was exploited as a zero-day. 

Nevertheless, it’s encouraging to see Broadcom promptly update its security advisory when potential exploitation of a vulnerability is detected. In contrast, the company has previously faced criticism for delaying such warnings even when exploitation was known for extended periods.

Related: Scattered Spider Targeting VMware vSphere Environments

Related: 2024 VMware Flaw Now in Attackers’ Crosshairs

Related: Exploit for VMware Zero-Day Flaws Likely Built a Year Before Public Disclosure

Related Content

Vulnerabilities

CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.

Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.

Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.

Vulnerabilities

CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.

Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

Vulnerabilities

The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.

Vulnerabilities

More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

Vulnerabilities

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version