CVE-2026-22721Patch(vmware / aria_operations)

MEDIUMCVSS 7.2 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch vmware aria_operations systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 .

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aria_operations
  • cloud_foundation
  • telco_cloud_infrastructure
  • telco_cloud_platform

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 18 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 12 signals
  • Disclosure: 5 classified signals
  • General: 4 classified signals
  • Peaked 8d ago at 4 mentions (2026-02-24); latest day: 1
  • 18 total mentions across 9 days

Affected systems

Vendors
Products
aria_operationscloud_foundationtelco_cloud_infrastructuretelco_cloud_platform

Deep dive

Activity timeline18 mentions / 9d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-25: 2Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-16: 1Mentions · 2026-03-18: 4Mentions · 2026-03-19: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-02-24: 4Patch / Workaround · 2026-02-25: 2Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 102-2402-2502-2602-2703-0303-0403-1603-1803-19
Signal classification4 categories
Patch
738.9%
Disclosure
527.8%
General
422.2%
Active Exploitation
211.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-244
Patch4
2026-02-252
Patch2
2026-02-262
Disclosure2
2026-02-272
Disclosure1General1
2026-03-031
Active Exploitation1
2026-03-041
Active Exploitation1
2026-03-161
General1
2026-03-184
Disclosure1General2Patch1
2026-03-191
Disclosure1
Full discourse18 posts
  • Enno Rey@Enno_Insinuator
    Disclosure

    Vulnerabilities in Broadcom VMware Aria Operations: Privilege Escalation (CVE-2025-41245 / CVE-2026-22721), via @Insinuator https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-cve-2026-22721/

    Post summary

    The post announces two privilege escalation vulnerabilities (CVE‑2025‑41245 and CVE‑2026‑22721) affecting Broadcom VMware Aria Operations, attributing the information to @Insinuator.

    070952.3K
    7.4K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Vulnerabilities in Broadcom VMware Aria Operations: Privilege Escalation (CVE-2025-41245 / CVE-2026-22721) https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-cve-2026-22721/

    Post summary

    The title announces two privilege‑escalation CVEs in Broadcom VMware Aria Operations, but offers no further technical or exploitation details.

    060831.4K
    153.3K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Patch

    🚨 ALERTĂ: Vulnerabilități identificate la nivelul VMWare (CVE-2026-22719, CVE-2026-22720 și CVE-2026-22721) 🔎 Se recomandă verificarea urgentă a versiunilor utilizate și aplicarea măsurilor de remediere disponibile. 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitati-identificate-la-nivelul-vmware #DNSC #CyberAlert #CVE https://t.co/ujuCZPQ3h9

    Post summary

    An alert announces newly identified VMware vulnerabilities (CVE-2026-22719, CVE-2026-22720, CVE-2026-22721) and urges users to verify versions and apply available remediation measures.

    11010167
    4.6K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    VMSA-2026-0001: VMware Aria Operations updates address multiple vulnerabilities (CVE-2026-22719, CVE-2026-22720 and CVE-2026-22721) https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947

    Post summary

    Broadcom released updates for VMware Aria Operations to fix CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721.

    01020679
    6.7K followersView on X
  • robin🪶@rob_OSINT
    General

    The Hebrew University claim is a classic case of Void Manticore theater. By exploiting CVE-2026-22719 (Aria Operations RCE) or CVE-2026-22721 (vCenter PrivEsc), they get the administrative "visuals" to claim a total wipe.

    Post summary

    The passage notes two CVEs and their basic classifications but provides no further details on PoC, exploitation, patches, or debunking.

    1001048
    505 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Severe vulnerabilities in #VMware Aria Operations including #CVE-2026-22720, #CVE-2026-22721 & #CVE-2026-22719 (CVSS 8.1) allow RCE during support-assisted product migration. Immediate action is critical to protect your systems. https://ccb.belgium.be/advisories/warning-severe-vulnerabilities-vmware-products-including-vmware-aria-operations-could-be #Patch #Patch

    Post summary

    The advisory warns of severe RCE vulnerabilities (CVE‑2026‑22719/20/21) in VMware Aria Operations with CVSS 8.1 and urges immediate patching via the provided link.

    01010249
    7.2K followersView on X
  • Lucas@lucasverdan
    Disclosure

    🛑 VMware Aria Operations flaws enable credential theft and privilege esca… CVE-2025-41245 and CVE-2026-22721 let low-privileged users escalate and extract credentials… 🔗 Details → https://invaders.ie/resources/blog/vulnerability/vmware-aria-operations-flaws-enable-credential-theft-and-privilege-escalation

    Post summary

    The tweet announces VMware Aria Operations CVEs (CVE‑2025‑41245 and CVE‑2026‑22721) that enable credential theft and privilege escalation, with a link to a detailed blog post.

    0000083
    309 followersView on X
  • DPR Recovery@GoldenPhone
    General

    @ciberseguridad Vulnerabilidades en Broadcom VMware Aria Operations: Escalada de privilegios (CVE-2025-41245 / CVE-2026-22721) https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-cve-2026-22721/

    Post summary

    The tweet announces privilege escalation vulnerabilities (CVE-2025-41245, CVE-2026-22721) in Broadcom VMware Aria Operations and provides a link for further information, but offers no technical or operational details.

    0000095
    52 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    VMware Aria Ops flaws (CVE-2025-41245 / CVE-2026-22721) allow privilege escalation from vCenter user → full admin, enabling credential theft (vCenter, VIDM, VCD) and takeover of connected environments; patch available, disable vCenter login if exposed https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-cve-2026-22721/

    Post summary

    The announcement reports privilege‑escalation vulnerabilities in VMware Aria Ops, confirms that an official patch exists, and advises disabling exposed vCenter logins as a mitigation.

    00000118
    295 followersView on X
  • xkzDB@xkzdb
    Active Exploitation

    🚨 CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw impacting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. The high-severity vulnerability, CVE-2026-22719 (CVSS score: 8.1), has been described as a case of command injection that could allow an unauthenticated attacker to execute arbitrary commands. <<<IMPORTANT>>> ⚡️ Added to CISA KEV Catalog March 3, 2026 ⚡️ Affects VMware Aria Operations during support-assisted product migration ⚡️ Broadcom VMSA-2026-0001 patches it along with CVE-2026-22720 (XSS) and CVE-2026-22721 (priv esc) ⚡️ Federal agencies must remediate by March 24, 2026 ⚡️ Broadcom aware of potential exploitation but cannot confirm Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA added CVE-2026-22719 to its KEV catalog, confirming active exploitation in the wild, noting a command injection flaw with CVSS 8.1, and Broadcom has released a patch.

    0000051
    319 followersView on X
  • xkzDB@xkzdb
    Active Exploitation

    🚨 CISA has added VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks. <<<IMPORTANT>>> ⚡️ CVE-2026-22719: Command injection RCE (CVSS 8.1) in VMware Aria Operations ⚡️ Allows unauthenticated attacker to execute arbitrary commands during support-assisted product migration ⚡️ Part of Broadcom VMSA-2026-0001 advisory with patches available ⚡️ Workaround for CVE-2026-22719 in KB430349 ⚡️ Also patches CVE-2026-22720 (XSS, CVSS 8.0) and CVE-2026-22721 (Priv Esc, CVSS 6.2) ⚡️ Affects VMware Cloud Foundation, Telco Cloud Platform/Infrastructure Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA has identified CVE-2026-22719 as actively exploited, with detailed technical info and available patches/workarounds.

    0000082
    212 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Disclosure

    VMware Aria Operationsに複数の脆弱性(CVE-2026-22719 / CVE-2026-22720 / CVE-2026-22721) https://rocket-boys.co.jp/security-measures-lab/vmware-aria-operations-multiple-vulnerabilities-cve-2026-22719-cve-2026-22720-cve-2026-22721/

    Post summary

    The post announces that VMware Aria Operations has multiple vulnerabilities identified as CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721, linking to a detailed article.

    0000078
    43 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    VMware Aria Operationsに複数の脆弱性(CVE-2026-22719 / CVE-2026-22720 / CVE-2026-22721) https://rocket-boys.co.jp/security-measures-lab/vmware-aria-operations-multiple-vulnerabilities-cve-2026-22719-cve-2026-22720-cve-2026-22721/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post lists several CVEs for VMware Aria Operations without providing additional technical details, PoC, or exploitation information.

    00000114
    320 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22721 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnera… https://www.cve.org/CVERecord?id=CVE-2026-22721

    Post summary

    The text announces a privilege escalation vulnerability (CVE‑2026‑22721) in VMware Aria Operations that can be exploited by users with vCenter privileges.

    00000148
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22721 Privilege Escalation in VMware Aria Operations https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22721

    Post summary

    A new privilege escalation vulnerability (CVE-2026-22721) in VMware Aria Operations has been disclosed, with a link to a vulnerability details page.

    0000039
    4.0K followersView on X
  • Exc.@exc_actual
    Patch

    Ether ai is putting in some work or the community is Broadcom patches 3 VMware Aria Operations vulns: CVE-2026-22719 (unauth command injection → RCE during migration), CVE-2026-22720 (stored XSS), CVE-2026-22721 (priv esc). Update now; no in-wild exploits yet. #CyberSec #VMware https://t.co/3tNWYzBR8F

    Post summary

    Broadcom has released patches for three VMware Aria Operations vulnerabilities (CVE-2026-22719, CVE-2026-22720, CVE-2026-22721) covering command injection, XSS, and privilege escalation; no active exploitation reported yet.

    0000074
    12 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Broadcom Patches VMware Aria Operations Bugs Enabling Unauth Command Injection → Potential RCE Broadcom fixed multiple VMware Aria Operations flaws, including CVE-2026-22719 (CVSS 8.1) an unauthenticated command-injection that can lead to remote code execution during support-assisted product migration, plus CVE-2026-22720 (stored XSS) and CVE-2026-22721 (privilege escalation). Patch immediately (Aria Ops 8.18.6 / VCF & vSphere Foundation 9.0.2.0) and review exposure/migration workflows since VMware bugs are frequently targeted after disclosure. 🎯 Target: Global/Enterprises using VMware Aria Operations #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/vmware-aria-operations-vulnerability-could-allow-remote-code-execution/

    Post summary

    Broadcom released patches for VMware Aria Operations vulnerabilities, including CVE-2026-22719, and urged users to update to specific versions and review migration workflows.

    0000077
    211 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Broadcom Patches High-Severity VMware Aria Operations Bugs Enabling Remote Attacks Broadcom released updates for VMware Aria Operations to fix multiple flaws, including an unauthenticated command injection (CVE-2026-22719, CVSS 8.1) that can be exploited remotely during support-assisted product migration to run arbitrary commands/RCE, plus a stored XSS (CVE-2026-22720, CVSS 8.0) and a privilege-escalation bug (CVE-2026-22721, CVSS 6.2). Organizations should urgently patch (Aria Ops v8.18.6 / VCF & vSphere Foundation v9.0.2.0) and review exposure of Aria Ops interfaces to reduce takeover risk. 🎯 Target: Global/Enterprises using VMware Aria Operations #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/188445/security/vmware-aria-operations-flaws-could-enable-remote-attacks.html

    Post summary

    Broadcom released patches for VMware Aria Operations to fix high‑severity vulnerabilities—unauthenticated command injection, stored XSS, and privilege escalation—and urges organizations to apply the updates immediately.

    0000073
    211 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarearia_operations---
Appvmwarecloud_foundation---
Appvmwaretelco_cloud_infrastructure---
Appvmwaretelco_cloud_platform---

Explore more