Malware & Threats

VMware Confirms Live Exploits Hitting Just-Patched Security Flaw

VMware updates a critical-level bulletin: “VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild.”

VMware updates a critical-level bulletin: “VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild.”

Less than two weeks after shipping urgent patches to cover security defects in its Aria Operations for Networks product, VMware says hackers have started launching exploits in the wild.

The virtualization technology giant on Tuesday updated a critical-level bulletin with a blunt warning to businesses running the network monitoring software: “VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild.”

The live exploits, first flagged by GreyNoise, target the CVE-2023-20887 command injection vulnerability that carries a CVSS severity score of 9.8/10.

“A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution,” VMware said in an advisory released earlier this month.

In all, VMware documented three critical-severity vulnerabilities that expose businesses to remote code execution and information disclosure attacks. 

The VMware Aria Operations for Networks, formerly vRealize Network Insight, is used by enterprises to monitor, discover and analyze networks and applications to build secure network infrastructure across clouds.

Advertisement. Scroll to continue reading.

Related: VMware Confirms Exploit Code for Critical vRealize Vulnerabilities

Related: VMware Patches High-Severity Vulnerabilities in vRealize Operations

Related: VMware Patches Pre-Auth Code Execution Flaw in Logging Product

Related Content

ICS/OT

Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets.

Vulnerabilities

The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

Vulnerabilities

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.

Vulnerabilities

A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.

Vulnerabilities

The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.

Vulnerabilities

The patch was announced as Broadcom is attending the Pwn2Own hacking competition in Berlin this week.

Vulnerabilities

The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version