CVE-2026-22720Patch(vmware / aria_operations)

MEDIUMCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch vmware aria_operations systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aria_operations
  • cloud_foundation
  • telco_cloud_infrastructure
  • telco_cloud_platform

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 4 mentions (2026-02-24); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
aria_operationscloud_foundationtelco_cloud_infrastructuretelco_cloud_platform

Deep dive

Activity timeline12 mentions / 6d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-25: 3Mentions · 2026-02-26: 1Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-02-24: 4Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 102-2402-2502-2602-2703-0303-04
Signal classification4 categories
Patch
433.3%
Disclosure
325.0%
General
325.0%
Active Exploitation
216.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure1Patch3
2026-02-253
Disclosure1General1Patch1
2026-02-261
Disclosure1
2026-02-272
General2
2026-03-031
Active Exploitation1
2026-03-041
Active Exploitation1
Full discourse12 posts
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ: Vulnerabilități identificate la nivelul VMWare (CVE-2026-22719, CVE-2026-22720 și CVE-2026-22721) 🔎 Se recomandă verificarea urgentă a versiunilor utilizate și aplicarea măsurilor de remediere disponibile. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-identificate-la-nivelul-vmware #DNSC #CyberAlert #CVE https://t.co/ujuCZPQ3h9

    Post summary

    The tweet announces newly identified VMware CVEs (CVE-2026-22719, CVE-2026-22720, CVE-2026-22721) and urges users to verify versions and apply available remediation measures.

    11010167
    4.6K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    VMSA-2026-0001: VMware Aria Operations updates address multiple vulnerabilities (CVE-2026-22719, CVE-2026-22720 and CVE-2026-22721) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947

    Post summary

    Broadcom released updates for VMware Aria Operations to fix CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721.

    01020679
    6.7K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Severe vulnerabilities in #VMware Aria Operations including #CVE-2026-22720, #CVE-2026-22721 & #CVE-2026-22719 (CVSS 8.1) allow RCE during support-assisted product migration. Immediate action is critical to protect your systems. https://ccb.belgium.be/advisories/warning-severe-vulnerabilities-vmware-products-including-vmware-aria-operations-could-be #Patch #Patch

    Post summary

    The advisory warns of severe RCE vulnerabilities in VMware Aria Operations (CVSS 8.1) and urges immediate action, but it does not provide PoC, exploit code, or patch details.

    01010249
    7.2K followersView on X
  • xkzDB@xkzdb
    Active Exploitation

    🚨 CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw impacting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. The high-severity vulnerability, CVE-2026-22719 (CVSS score: 8.1), has been described as a case of command injection that could allow an unauthenticated attacker to execute arbitrary commands. <<<IMPORTANT>>> ⚡️ Added to CISA KEV Catalog March 3, 2026 ⚡️ Affects VMware Aria Operations during support-assisted product migration ⚡️ Broadcom VMSA-2026-0001 patches it along with CVE-2026-22720 (XSS) and CVE-2026-22721 (priv esc) ⚡️ Federal agencies must remediate by March 24, 2026 ⚡️ Broadcom aware of potential exploitation but cannot confirm Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA has added CVE-2026-22719 to its KEV catalog, confirming active exploitation in the wild and providing patch information from Broadcom.

    0000051
    319 followersView on X
  • xkzDB@xkzdb
    Active Exploitation

    🚨 CISA has added VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks. <<<IMPORTANT>>> ⚡️ CVE-2026-22719: Command injection RCE (CVSS 8.1) in VMware Aria Operations ⚡️ Allows unauthenticated attacker to execute arbitrary commands during support-assisted product migration ⚡️ Part of Broadcom VMSA-2026-0001 advisory with patches available ⚡️ Workaround for CVE-2026-22719 in KB430349 ⚡️ Also patches CVE-2026-22720 (XSS, CVSS 8.0) and CVE-2026-22721 (Priv Esc, CVSS 6.2) ⚡️ Affects VMware Cloud Foundation, Telco Cloud Platform/Infrastructure Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA has identified CVE-2026-22719 as actively exploited, with detailed technical info and available patches/workarounds.

    0000082
    212 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    General

    VMware Aria Operationsに複数の脆弱性(CVE-2026-22719 / CVE-2026-22720 / CVE-2026-22721) https://rocket-boys.co.jp/security-measures-lab/vmware-aria-operations-multiple-vulnerabilities-cve-2026-22719-cve-2026-22720-cve-2026-22721/

    Post summary

    The post announces multiple CVEs affecting VMware Aria Operations but offers no further technical or operational details.

    0000078
    43 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    VMware Aria Operationsに複数の脆弱性(CVE-2026-22719 / CVE-2026-22720 / CVE-2026-22721) https://rocket-boys.co.jp/security-measures-lab/vmware-aria-operations-multiple-vulnerabilities-cve-2026-22719-cve-2026-22720-cve-2026-22721/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post lists several CVEs affecting VMware Aria Operations but provides no further details about exploitation, patches, or technical aspects.

    00000114
    320 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22720 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject scrip… https://www.cve.org/CVERecord?id=CVE-2026-22720

    Post summary

    CVE-2026-22720 is a stored XSS flaw in VMware Aria Operations that allows users with benchmark‑creation privileges to inject scripts. No PoC, exploit code, or active exploitation is reported, and no patch or workaround is mentioned.

    00000144
    56.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos VMware ❗ CVE-2026-22720 ❗ CVE-2026-22719 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-vmware-5/ https://t.co/QlUkK3N7bl

    Post summary

    The tweet lists two VMware CVEs and directs readers to a link for more information, but offers no additional details or context.

    00000133
    6.6K followersView on X
  • Exc.@exc_actual
    Patch

    Ether ai is putting in some work or the community is Broadcom patches 3 VMware Aria Operations vulns: CVE-2026-22719 (unauth command injection → RCE during migration), CVE-2026-22720 (stored XSS), CVE-2026-22721 (priv esc). Update now; no in-wild exploits yet. #CyberSec #VMware https://t.co/3tNWYzBR8F

    Post summary

    Broadcom has released patches for three VMware Aria Operations vulnerabilities (CVE-2026-22719, CVE-2026-22720, CVE-2026-22721) with detailed technical descriptions; no active exploitation has been reported yet.

    0000074
    12 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Broadcom Patches VMware Aria Operations Bugs Enabling Unauth Command Injection → Potential RCE Broadcom fixed multiple VMware Aria Operations flaws, including CVE-2026-22719 (CVSS 8.1) an unauthenticated command-injection that can lead to remote code execution during support-assisted product migration, plus CVE-2026-22720 (stored XSS) and CVE-2026-22721 (privilege escalation). Patch immediately (Aria Ops 8.18.6 / VCF & vSphere Foundation 9.0.2.0) and review exposure/migration workflows since VMware bugs are frequently targeted after disclosure. 🎯 Target: Global/Enterprises using VMware Aria Operations #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/

    Post summary

    Broadcom released patches for VMware Aria Operations vulnerabilities CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721, including an unauthenticated command injection that could lead to RCE; organizations should apply the updates immediately.

    0000077
    211 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Broadcom Patches High-Severity VMware Aria Operations Bugs Enabling Remote Attacks Broadcom released updates for VMware Aria Operations to fix multiple flaws, including an unauthenticated command injection (CVE-2026-22719, CVSS 8.1) that can be exploited remotely during support-assisted product migration to run arbitrary commands/RCE, plus a stored XSS (CVE-2026-22720, CVSS 8.0) and a privilege-escalation bug (CVE-2026-22721, CVSS 6.2). Organizations should urgently patch (Aria Ops v8.18.6 / VCF & vSphere Foundation v9.0.2.0) and review exposure of Aria Ops interfaces to reduce takeover risk. 🎯 Target: Global/Enterprises using VMware Aria Operations #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/188445/security/vmware-aria-operations-flaws-could-enable-remote-attacks.html

    Post summary

    Broadcom released patches for VMware Aria Operations to fix high‑severity vulnerabilities—including unauthenticated command injection, stored XSS, and privilege escalation—and urges organizations to apply the updates immediately.

    0000073
    211 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarearia_operations---
Appvmwarecloud_foundation---
Appvmwaretelco_cloud_infrastructure---
Appvmwaretelco_cloud_platform---

Explore more