CVE-2026-22719Active Exploitation(vmware / aria_operations)

CRITICALCVSS 8.1 · HIGHCISA KEV

Exploitation observed; activity peaked at 68 mentions and remains active

Immediate actions

  • Patch vmware aria_operations systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aria_operations
  • cloud_foundation
  • telco_cloud_infrastructure
  • telco_cloud_platform

Threat summary

  • Active exploitation appears in 103 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 140 mentions across 21 observed days

What's happening

  • Active exploitation reported across 103 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 56 signals
  • Technical details provided in 72 signals
  • Disclosure: 13 classified signals
  • Peaked 15d ago at 68 mentions (2026-03-04); latest day: 3
  • 140 total mentions across 21 days

Affected systems

Vendors
Products
aria_operationscloud_foundationtelco_cloud_infrastructuretelco_cloud_platform

Deep dive

Activity timeline140 mentions / 21d
017345168Mentions · 2026-02-24: 7Mentions · 2026-02-25: 6Mentions · 2026-02-26: 7Mentions · 2026-02-27: 2Mentions · 2026-03-03: 8Mentions · 2026-03-04: 68Mentions · 2026-03-05: 15Mentions · 2026-03-06: 6Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 4Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-16: 1Mentions · 2026-03-17: 2Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-03-30: 1Mentions · 2026-04-02: 1Mentions · 2026-04-15: 1Mentions · 2026-05-08: 3PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-02-26: 1Exploit Tool / Code · 2026-03-05: 1Active Exploitation · 2026-03-03: 7Active Exploitation · 2026-03-04: 64Active Exploitation · 2026-03-05: 13Active Exploitation · 2026-03-06: 5Active Exploitation · 2026-03-09: 2Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 2Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-24: 2Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-05-08: 2Patch / Workaround · 2026-02-24: 7Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-02-26: 5Patch / Workaround · 2026-03-03: 4Patch / Workaround · 2026-03-04: 24Patch / Workaround · 2026-03-05: 5Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-09: 3Patch / Workaround · 2026-03-17: 2Patch / Workaround · 2026-03-25: 1Technical Details · 2026-02-24: 5Technical Details · 2026-02-25: 5Technical Details · 2026-02-26: 2Technical Details · 2026-03-03: 7Technical Details · 2026-03-04: 33Technical Details · 2026-03-05: 6Technical Details · 2026-03-06: 3Technical Details · 2026-03-07: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 102-2402-2603-0303-0503-0703-0903-1103-1703-2504-0205-08
Signal classification5 categories
Active Exploitation
10071.4%
Patch
1913.6%
Disclosure
139.3%
General
75.0%
PoC
10.7%
Referenced assets84 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-247
Disclosure1Patch6
2026-02-256
Disclosure3General1Patch2
2026-02-267
Disclosure2Patch5
2026-02-272
Disclosure2
2026-03-038
Active Exploitation6Disclosure2
2026-03-0468
Active Exploitation63Disclosure2Patch2PoC1
2026-03-0515
Active Exploitation12Disclosure1General1Patch1
2026-03-066
Active Exploitation5General1
2026-03-071
General1
2026-03-081
General1
2026-03-094
Active Exploitation2Patch2
2026-03-101
Active Exploitation1
2026-03-112
Active Exploitation2
2026-03-161
Active Exploitation1
2026-03-172
Active Exploitation1Patch1
2026-03-242
Active Exploitation2
2026-03-251
Active Exploitation1
2026-03-301
General1
2026-04-021
Active Exploitation1
2026-04-151
Active Exploitation1
2026-05-083
Active Exploitation2General1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🛑 A command-injection bug in VMware Aria Operations is now in CISA’s KEV catalog. The flaw — CVE-2026-22719 (CVSS 8.1) — could let unauthenticated attackers run arbitrary commands during migration workflows. 🔗 Details → https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html

    Post summary

    CISA has added CVE‑2026‑22719, a command‑injection flaw in VMware Aria Operations, to its KEV catalog, indicating it is being actively exploited in the wild.

    5283891110.6K
    1.1M followersView on X
  • CISA Cyber@CISACyber
    Disclosure

    🛡️ We added Qualcomm memory corruption vulnerability CVE-2026-21385 & Broadcom VMware Aria Operations command injection vulnerability CVE-2026-22719 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity https://t.co/cgLZwOA2pf

    Post summary

    The DHS announced that Qualcomm and Broadcom vulnerabilities were added to the KEV catalog and urged organizations to apply mitigations.

    4204571011.9K
    292.4K followersView on X
  • ExWareLabs@ExWareLabs
    Disclosure

    CVE-2026-22719 : VMware Aria Operations contains a command injection vulnerability https://t.co/fpLQ8VhMQ3

    Post summary

    A command injection vulnerability (CVE-2026-22719) has been disclosed in VMware Aria Operations.

    010045132.9K
    775 followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-22719 (CVSS 8.1) is an actively exploited command injection vulnerability in VMware Aria Operations that allows unauthenticated attackers to achieve remote code execution during product migration. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJ2bXdhcmUtdlNwaGVyZS1XZWItQ2xpZW50IiB8fCBhcHA9InZtd2FyZS1BcmlhIg== 🎯492+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="vmware-vSphere-Web-Client" || app="vmware-Aria" 🔖Refer: https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2026‑22719 is an actively exploited command injection flaw in VMware Aria Operations (CVSS 8.1) that allows unauthenticated remote code execution during migration, with evidence from FOFA and external reports but no patch or PoC provided.

    011036173.8K
    13.6K followersView on X
  • DigiByte Developers@DGBDevs
    Active Exploitation

    CISA flagged CVE-2026-22719 — VMware Aria Operations RCE actively exploited in the wild. Management plane software is a permanent attack surface. $DGB has no management plane. Open-source MIT C++, 12 years of public scrutiny. No orchestration layer to exploit.

    Post summary

    CISA flagged the VMware Aria Operations RCE (CVE-2026-22719) as actively exploited in the wild, with no PoC, exploit tool, patch, or false‑positive claim mentioned.

    190240944
    1.4K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    CISA has identified CVE-2026-22719 as an actively exploited vulnerability in VMware Aria Operations and added it to the KEV catalog.

    11030697
    193.5K followersView on X
  • Blue Team News@blueteamsec1
    Active Exploitation

    CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog http://dlvr.it/TRrHXH #CyberSecurity #VMware #CISA #Vulnerability #CVE202622719 https://t.co/EQb7ETapuF

    Post summary

    CISA reports that VMware Aria Operations CVE-2026-22719 is being actively exploited and adds it to the KEV catalog.

    01030577
    56.2K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Broadcom warns of a high-severity RCE flaw (CVE-2026-22719) in VMware Aria Operations. Attackers can execute commands during system migrations. Patch now! #VMware #Broadcom #CVE #CyberSecurity #AriaOperations #RCE #InfoSec #CloudSecurity #Vulnerability https://securityonline.info/critical-vmware-aria-operations-flaw-allows-rce-during-system-upgrades/

    Post summary

    Broadcom alerts to a high‑severity RCE vulnerability in VMware Aria Operations (CVE‑2026‑22719) and urges immediate patching.

    01021398
    10.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/3追加) 🛡️No.1531 CVE-2026-22719 Broadcom VMware Aria Operations Command Injection Vulnerability ============= CVSSスコア: 8.1 (Base) / Vmware CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:コマンドインジェクション (CWE-77 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、サポート支援により製品移行中の VMware Aria Operations 環境において、任意のコマンドを実行される恐れがあります。 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 https://knowledge.broadcom.com/external/article/430349 🛡️No.1532 CVE-2026-21385 Qualcomm Multiple Chipsets Memory Corruption Vulnerability ============= CVSSスコア: 7.8 (Base) / Qualcomm, Inc. CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 種別:整数オーバーフローまたはラップアラウンド (/../filedir) (CWE-190 / Qualcomm, Inc.) 深刻度:重要 ---------------------- 悪用時影響: Qualcommチップセットには、メモリ破壊の脆弱性が存在し、認証済みの攻撃者によりローカル上で悪用される恐れがあります。 https://source.android.com/docs/security/bulletin/2026/2026-03-01 CISA Adds Two Known Exploited Vulnerabilities to Catalog https://www.cisa.gov/news-events/alerts/2026/03/03/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed active exploitation of two CVEs, providing detailed technical information and vendor advisory links, but no PoC or exploit code was disclosed.

    000213.2K
    42.6K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ: Vulnerabilități identificate la nivelul VMWare (CVE-2026-22719, CVE-2026-22720 și CVE-2026-22721) 🔎 Se recomandă verificarea urgentă a versiunilor utilizate și aplicarea măsurilor de remediere disponibile. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-identificate-la-nivelul-vmware #DNSC #CyberAlert #CVE https://t.co/ujuCZPQ3h9

    Post summary

    An alert announces three new VMware CVEs and urges users to check versions and apply available remediation measures.

    11010167
    4.6K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    VMSA-2026-0001: VMware Aria Operations updates address multiple vulnerabilities (CVE-2026-22719, CVE-2026-22720 and CVE-2026-22721) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947

    Post summary

    VMware Aria Operations released updates to patch CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721.

    01020679
    6.7K followersView on X
  • robin🪶@rob_OSINT
    Active Exploitation

    The Hebrew University claim is a classic case of Void Manticore theater. By exploiting CVE-2026-22719 (Aria Operations RCE) or CVE-2026-22721 (vCenter PrivEsc), they get the administrative "visuals" to claim a total wipe.

    Post summary

    The Instagram post claims that the Hebrew University exploited CVE-2026-22719 (RCE in Aria Operations) and CVE-2026-22721 (PrivEsc in vCenter) to gain administrative access and proclaim a total wipe, though no PoC or patch information is provided.

    1001048
    505 followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2026-22719  ⚠️ VMware Aria Operations – Actively Exploited RCE (CISA KEV)  CISA has added CVE-2026-22719 to its KEV catalogue following reports of active exploitation impacting Broadcom VMware environments.  The flaw is an unauthenticated command injection vulnerability that can result in remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  Impacted products include VMware Aria Operations (<8.18.6), VMware Cloud Foundation (<9.0.2.0 / <5.2.3), and VMware vSphere Foundation 9.x (<9.0.2.0).  Apply patches or the vendor workaround immediately.  Modat Magnify Query: web.html~"com.vmware.vsphere.client" OR web.title~"VMware Cloud Director Availability" OR web.title~"VMware Aria Operations"  Results might contain honeypots.  The platform: https://magnify.modat.io #threatintel #vulnerability #CVE202622719 #VMware #AriaOperations #vSphere #CloudFoundation #RCE #CISA #KEV #infosec #ModatMagnify

    Post summary

    CISA identifies CVE-2026-22719 as an actively exploited unauthenticated command injection flaw in VMware Aria Operations and related products, urging immediate patching or vendor workarounds to prevent remote code execution.

    00011111
    291 followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    A command injection vulnerability in VMware Aria Operations (CVE-2026-22719) is being actively exploited, allowing unauthenticated attackers to execute commands and potentially take over entire virtual infrastructures. If your workplace uses VMware Aria Operations versions 8.0 through 8.18.5 or 9.0 through 9.0.1, update to version 8.18.6 or 9.0.2.0 immediately through your VMware admin console. If patching takes longer than 48 hours, run the workaround script Broadcom provides in their advisory to block exploitation during migration windows. 🚨 #CyberNewsLive https://darkreading.com/cloud-security/vmware-aria-operations-bug-exploited-cloud-risk

    Post summary

    VMware Aria Operations is experiencing active exploitation via a command injection flaw (CVE-2026-22719); users are urged to patch to 8.18.6/9.0.2.0 or apply Broadcom’s workaround script.

    0101060
    1.5K followersView on X
  • ctrlaltnod@ctrlaltnod
    Active Exploitation

    VMware Aria Operations Flaw Actively Exploited by Hackers - Critical CVE-2026-22719 vulnerability in VMware Aria Operations allows remote code execution. CISA warns of active exploitation requiring urgent patches. https://www.ctrlaltnod.com/news/vmware-aria-operations-flaw-actively-exploited-cisa-issues-warning/

    Post summary

    The article reports that CVE-2026-22719 in VMware Aria Operations is being exploited in the wild with RCE, prompting CISA to urge urgent patching.

    01010241
    283 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html

    Post summary

    CISA has identified CVE-2026-22719 as an actively exploited vulnerability in VMware Aria Operations and added it to the KEV catalog.

    100101.1K
    152.3K followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Warns VMware Aria Operations RCE (CVE-2026-22719) Is Being Actively Exploited CISA added CVE-2026-22719 (command injection) in VMware Aria Operations to the KEV catalog after confirming in-the-wild exploitation; the flaw can enable unauthenticated remote code execution during support-assisted product migrations. Organizations should patch or apply vendor mitigations immediately; U.S. federal agencies have a March 24, 2026 remediation deadline. 🎯 Target: Global/Enterprise (VMware Aria Operations) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/vmware-aria-operations-vulnerability-2/

    Post summary

    CISA confirms CVE-2026-22719 is actively exploited in the wild, urging immediate patching of VMware Aria Operations.

    0101057
    262 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    VMware Aria Operations の脆弱性 CVE-2026-22719/22720/22721 が FIX:リモート・コード実行の恐れ https://iototsecnews.jp/2026/02/24/vmware-aria-flaws-enable-attackers-to-execute-remote-code/ Broadcom から発行されたセキュリティ・アドバイザリ VMSA-2026-0001 は、インフラ管理の中核を担う VMware Aria Operations で発見された深刻な脆弱性を解説するものです。今回の報告で最も危険なのが、コマンド・インジェクションの脆弱性である CVE-2026-22719 です。これは製品の移行 (Migration) プロセス中に、外部からの入力が適切に検証されないという不備を突くものであり、ユーザー名やパスワードといった認証情報を必要としない、リモートからの任意のコマンド実行を引き起こすものです。 #AriaOperations #CVE202622719 #CVE202622720 #CVE202622721 #VMware #Vulnerability

    Post summary

    Broadcom’s advisory explains three CVEs in VMware Aria Operations, emphasizing a command‑injection flaw that permits unauthenticated remote code execution during migration, and notes that a fix has been issued.

    01010176
    483 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Severe vulnerabilities in #VMware Aria Operations including #CVE-2026-22720, #CVE-2026-22721 &amp; #CVE-2026-22719 (CVSS 8.1) allow RCE during support-assisted product migration. Immediate action is critical to protect your systems. https://ccb.belgium.be/advisories/warning-severe-vulnerabilities-vmware-products-including-vmware-aria-operations-could-be #Patch #Patch

    Post summary

    The advisory highlights severe RCE vulnerabilities (CVE‑2026‑22719/20/21) in VMware Aria Operations with a CVSS score of 8.1, urging users to take immediate action to mitigate the risk.

    01010249
    7.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Broadcom released patches for VMware Aria Operations vulnerabilities, including CVE-2026-22719, a critical unauthenticated command injection allowing remote code execution. Fixed in vSphere Foundation 9.0.2.0. #VMware #RemoteCodeExecution #USA https://ift.tt/F9MtI2L

    Post summary

    Broadcom has released patches for VMware Aria Operations CVE-2026-22719, a critical unauthenticated command injection that allows remote code execution, fixed in vSphere Foundation 9.0.2.0.

    00020162
    3.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarearia_operations---
Appvmwarecloud_foundation---
Appvmwaretelco_cloud_infrastructure---
Appvmwaretelco_cloud_platform---

Explore more