VMware Aria Flaws Enable Attackers to Execute Remote Code
On Tue, Feb 24, 2026, Broadcom published security advisory VMSA-2026-0001, detailing three vulnerabilities in VMware Aria Operations. These vulnerabilities could enable remote execution of arbitrary commands.
On Tue, Feb 24, 2026, Broadcom published security advisory VMSA-2026-0001, detailing three vulnerabilities in VMware Aria Operations. These vulnerabilities could enable remote execution of arbitrary commands.
The vulnerabilities impact VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure. Patches are available for all affected versions.
The most critical vulnerability, identified as CVE-2026-22719, involves a command injection issue with a CVSSv3 score of 8.1. This flaw allows an unauthenticated attacker to execute arbitrary commands and achieve remote code execution during a support-assisted product migration. A workaround is provided in Broadcom Knowledge Base article KB430349.
CVE-2026-22720 is a stored cross-site scripting (XSS) vulnerability with a CVSSv3 score of 8.0. Attackers with privileges to create custom benchmarks can inject scripts to perform unauthorized actions within the Aria Operations interface. This issue was reported by Tobias Anders of Deutsche Telekom Security GmbH.
CVE-2026-22721 is a privilege escalation vulnerability with a CVSSv3 score of 6.2. It allows an attacker with existing privileges in vCenter to obtain full administrative access in VMware Aria Operations. This vulnerability was discovered by Sven Nobis and Lorin Lehawany of ERNW Enno Rey Netzwerke GmbH.
CVE ID CVSS Score Severity Vulnerability Type Attack Vector
CVE-2026-22719 8.1 Important Command Injection / RCE Network (Unauthenticated)
On Tue, Feb 24, 2026, Broadcom published security advisory VMSA-2026-0001, detailing three vulnerabilities in VMware Aria Operations.
CVE-2026-22720 8.0 Important Stored Cross-Site Scripting Network (Low Privileges)
CVE-2026-22721 6.2 Moderate Privilege Escalation Network (High Privileges)
Product Affected Version Fixed Version
VMware Aria Operations 8.x 8.18.6
VMware Cloud Foundation (VCF Operations) 9.x.x.x 9.0.2.0
VMware Cloud Foundation (Aria Operations) 5.x, 4.x KB92148
VMware Telco Cloud Platform 5.x, 4.x KB428241
VMware Telco Cloud Infrastructure 3.x, 2.x KB428241
Administrators are strongly advised to apply the available patches immediately. Organizations using VMware Aria Operations should prioritize upgrading to the specified fixed versions. The command injection vulnerability (CVE-2026-22719) is particularly critical due to its potential for unauthenticated remote exploitation. A temporary workaround via KB430349 is available for cases where immediate patching is not possible.
Based on reporting by GBHackers.



