SECURITYHIGHCVE-2026-22719

CISA Adds Actively Exploited VMware Aria Operations RCE

CISA has added CVE-2026-22719, a high-severity command injection vulnerability in VMware Aria Operations allowing unauthenticated remote code execution,...

Dylan H.

Security Team

March 4, 2026
4 min read
CISA Adds Actively Exploited VMware Aria Operations RCE

Actively exploited

Reported as exploited in the wild (e.g. CISA KEV). Patch or mitigate immediately.

Affected Products

  • VMware Aria Operations

Another VMware Flaw Under Active Attack

CISA has added CVE-2026-22719, a high-severity command injection vulnerability in VMware Aria Operations (formerly vRealize Operations), to its Known Exploited Vulnerabilities (KEV) catalog after confirming the flaw is being actively exploited in the wild.

The vulnerability allows an unauthenticated attacker to execute arbitrary commands, potentially achieving full remote code execution on affected systems.


Vulnerability Details

DetailValue
CVECVE-2026-22719
CVSS Score8.1 (High Severity)
TypeCommand Injection
Attack VectorNetwork — unauthenticated
ImpactRemote code execution
ConditionExploitable during support-assisted product migration
VendorBroadcom (VMware)
Patch ReleasedFebruary 24, 2026
KEV AdditionMarch 4, 2026
FCEB Patch DeadlineMarch 24, 2026

How the Vulnerability Works

The flaw exists in VMware Aria Operations and can be exploited by a malicious unauthenticated actor while support-assisted product migration is in progress. During this migration window, the vulnerability allows execution of arbitrary commands that can lead to full remote code execution on the underlying system.

While Broadcom released security patches on February 24, the gap between patch availability and active exploitation has left many organizations exposed.


Active Exploitation Confirmed

CISA confirmed the vulnerability is being actively exploited, though details remain limited:

  • Threat actors behind the exploitation have not been publicly identified
  • Scale of attacks is currently unknown
  • Targeted sectors have not been disclosed
  • The exploitation appears to target organizations mid-migration or with migration services still accessible

Remediation

Patching

Broadcom released security patches on February 24, 2026. Organizations should apply these immediately.

Temporary Workaround

For organizations unable to apply patches immediately, Broadcom has provided a temporary workaround — details are available in Broadcom's security advisory. However, the workaround should be treated as a stopgap, not a permanent solution.

Federal Mandate

Federal Civilian Executive Branch (FCEB) agencies are required to apply the fix by March 24, 2026, per CISA's KEV catalog requirements.


Impact Assessment

Impact AreaDescription
Affected environmentsAny organization running VMware Aria Operations
Migration riskOrganizations mid-migration are especially vulnerable
Access achievedFull RCE as an unauthenticated user
Enterprise exposureAria Operations is widely deployed for cloud infrastructure monitoring
Chained riskRCE on a monitoring platform could provide visibility into entire virtualized environments

Recommendations

For VMware Administrators

  1. Apply Broadcom's patches immediately — prioritize this over other maintenance tasks
  2. Audit migration service status — disable support-assisted migration endpoints if not actively in use
  3. Check for indicators of compromise on Aria Operations instances
  4. Restrict network access to Aria Operations management interfaces

For Security Teams

  1. Scan for CVE-2026-22719 across your environment using vulnerability management tools
  2. Monitor Aria Operations logs for unusual command execution or access patterns
  3. Verify patch deployment across all instances — shadow IT VMware deployments are common
  4. Implement network segmentation to isolate monitoring platforms from production workloads

Key Takeaways

  1. CVE-2026-22719 is the second VMware vulnerability added to CISA's KEV catalog in 2026
  2. Unauthenticated RCE on a monitoring platform is exceptionally dangerous — it provides attackers visibility into the entire infrastructure
  3. The migration-window attack surface is an unusual vector that organizations may not have accounted for in their threat models
  4. Patches have been available since February 24 — organizations that haven't applied them are now confirmed targets
  5. VMware/Broadcom products continue to be high-value targets for threat actors due to their prevalence in enterprise data centers