CISA Warns of Actively Exploited VMware Aria Operations Vulnerability (CVE-2026-22719)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in VMware Aria Operations, tracked as CVE-2026-22719, to its Known Exploited Vulnerabilities (KEV) catalog. This action signals that the agency believes the flaw is actively being exploited in attacks, posing a significant risk to organizations that rely on the enterprise monitoring platform. VMware Aria Operations is widely used to track the performance and health of servers, networks, and cloud infrastructure, making this vulnerability a concern for a broad range of businesses and government entities.

The addition to the KEV catalog means that federal civilian executive branch (FCEB) agencies are required to remediate the vulnerability by March 24, 2026, as mandated by Binding Operational Directive (BOD) 22-01. However, CISA strongly encourages all organizations, not just federal agencies, to prioritize addressing this and other vulnerabilities listed in the KEV catalog to bolster their cybersecurity posture. The KEV catalog was established to provide a focused list of vulnerabilities that present the most immediate and significant threats.

Understanding CVE-2026-22719: A Command Injection Vulnerability

CVE-2026-22719 is classified as a command injection vulnerability. According to Broadcom, the company that owns VMware, a malicious, unauthenticated attacker could exploit this flaw to execute arbitrary commands on vulnerable systems. This could potentially lead to remote code execution, granting the attacker significant control over the affected system. The vulnerability is particularly concerning due to the fact that it can be exploited without requiring any authentication, meaning anyone with network access could potentially attempt to compromise a system.

The vulnerability surfaces during support-assisted product migration, a process used to update or move VMware Aria Operations instances. This specific timing makes it a potential target for attackers who might attempt to exploit the vulnerability during routine maintenance or upgrade procedures. The vulnerability received a Common Vulnerability Scoring System (CVSS) score of 8.1, indicating a high level of severity. CISA’s announcement highlights the urgency of addressing this issue.

Broadcom’s Response and Mitigation Strategies

Broadcom initially disclosed and patched the vulnerability on February 24, 2026, as part of VMware Security Advisory VMSA-2026-0001. While Broadcom acknowledges reports of potential exploitation, the company states it cannot independently confirm these claims. Despite this, the agency is urging swift action to mitigate the risk. BleepingComputer reported on CISA’s flagging of the vulnerability.

For organizations unable to immediately apply the security patch, Broadcom has provided a workaround in the form of a shell script, “aria-ops-rce-workaround.sh.” This script must be executed as root on each Aria Operations Virtual Appliance node. The script is available through Broadcom’s knowledge base article 430349. Applying the patch remains the recommended solution, but the workaround offers a temporary measure to reduce the risk of exploitation.

Affected Products

The vulnerability impacts the following VMware products:

  • VMware Cloud Foundation and VMware vSphere Foundation 9.x.x.x (fixed in 9.0.2.0)
  • VMware Aria Operations 8.x (fixed in 8.18.6)

Organizations using these products should prioritize updating to the patched versions or implementing the provided workaround. The Hacker News detailed the affected products and fixes.

The Broader Context: CISA’s KEV Catalog and BOD 22-01

The inclusion of CVE-2026-22719 in CISA’s KEV catalog is part of a broader effort to address actively exploited vulnerabilities. The KEV catalog, established under BOD 22-01, aims to reduce the significant risk posed by known vulnerabilities that are frequently targeted by malicious cyber actors. BOD 22-01 requires FCEB agencies to remediate identified vulnerabilities within a specified timeframe.

While BOD 22-01 directly applies only to federal agencies, CISA emphasizes that all organizations should prioritize addressing vulnerabilities listed in the KEV catalog. This proactive approach is crucial in mitigating the risk of cyberattacks and protecting critical infrastructure. The KEV catalog is a “living list,” meaning CISA will continue to add vulnerabilities as they are identified and evidence of active exploitation emerges.

What is a Command Injection Vulnerability?

A command injection vulnerability occurs when an application allows an attacker to inject arbitrary commands into a system. This happens when user-supplied data is not properly validated or sanitized before being used in a system command. An attacker can then execute malicious commands on the server, potentially gaining control of the system or accessing sensitive data. The lack of authentication required to exploit CVE-2026-22719 significantly increases the risk, as it lowers the barrier to entry for potential attackers.

What Happens Next?

Federal agencies are required to address CVE-2026-22719 by March 24, 2026. Organizations outside the FCEB are strongly encouraged to follow suit and prioritize patching or implementing the workaround provided by Broadcom. The situation remains fluid, and further details regarding active exploitation attempts may emerge. Organizations should continue to monitor security advisories from CISA and Broadcom for updates and guidance.

The ongoing monitoring of exploitation attempts and the potential for new vulnerabilities to emerge underscore the importance of a robust and proactive cybersecurity strategy. This includes regular vulnerability scanning, patch management, and employee training on cybersecurity best practices. Staying informed about the latest threats and vulnerabilities is crucial for protecting against cyberattacks.

The next update from Broadcom regarding the confirmed exploitation of CVE-2026-22719 is expected in the coming weeks. Organizations should also monitor CISA’s website for any further guidance or updates related to this vulnerability.

Have thoughts on this critical security update? Share your comments and insights below, and please share this article with your network to help raise awareness about this important issue.

Leave a Comment