CISA Adds VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog After Reports of Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed a recently disclosed vulnerability affecting Broadcom’s VMware Aria Operations into its Known Exploited Vulnerabilities (KEV) catalog, citing evidence that attackers are actively leveraging the flaw.
Tracked as CVE-2026-22719 and rated with a CVSS score of 8.1, the issue is a command injection weakness that could enable an unauthenticated actor to run arbitrary commands on affected systems. Broadcom warned that exploitation could result in remote code execution during support-assisted product migration processes.
Broadcom addressed this defect alongside two related flaws: CVE-2026-22720, a stored cross-site scripting (XSS) issue, and CVE-2026-22721, a privilege-escalation bug that can allow administrative-level access. The vendor has released fixes in specific product builds to remediate these problems.
The patches are included in these updates: VMware Cloud Foundation and VMware vSphere Foundation 9.x.x.x are corrected in version 9.0.2.0, while VMware Aria Operations 8.x is fixed in version 8.18.6. Administrators should confirm their environment’s version and apply the appropriate updates as soon as possible.
For organizations that cannot immediately install the official updates, Broadcom offers a temporary mitigation: run the provided shell script named “aria-ops-rce-workaround.sh” with root privileges on each Aria Operations Virtual Appliance node to reduce exposure until the patch can be applied.
Details about how attackers are exploiting CVE-2026-22719, the identities of the threat actors, and the breadth of successful compromises remain unclear. Broadcom stated it has seen reports suggesting active exploitation but has not been able to independently verify those claims.
Given the active exploitation designation, Federal Civilian Executive Branch (FCEB) agencies are mandated to deploy the fixes by March 24, 2026. Organizations across the private sector should also prioritize remediation to limit the risk of remote code execution and privilege escalation.