Skip to main content
Mallory
Back to intelligence
widely-deployed-product-advisorycloud-service-vulnerabilityinternet-facing-service-vulnerability

Broadcom Patches VMware Aria Operations Flaws Enabling RCE During Support-Assisted Migrations

Updated 2mo agoFirst seen Feb 24, 20266 sources

Broadcom issued advisory VMSA-2026-0001 for VMware Aria Operations (formerly vRealize Operations), warning of three vulnerabilities affecting Aria Operations and bundled platforms including VMware Cloud Foundation and VMware Telco Cloud. The most severe issue, CVE-2026-22719 (CVSS 8.1), is a command injection flaw that can be exploited by an unauthenticated attacker to execute arbitrary commands and potentially achieve remote code execution specifically while a support-assisted product migration is in progress. Broadcom released patches and also documented a workaround for CVE-2026-22719 in its response matrix/KB guidance.

The advisory also covers CVE-2026-22720 (CVSS 8.0), a stored XSS issue where a user with privileges to create custom benchmarks can inject script to perform administrative actions, and CVE-2026-22721 (CVSS 6.2), a privilege escalation path where a user with vCenter access to Aria Operations can elevate to administrative control. Researchers Sven Nobis and Lorin Lehawany of ERNW were credited with reporting at least part of the findings. Impacted deployments include Aria Operations 8.x and related bundles across Cloud Foundation and Telco Cloud product lines; Broadcom’s fixed versions include updates such as Aria Operations 8.18.6 and Cloud Foundation 9.0.2.0, and organizations are advised to prioritize upgrades due to the lack of workarounds for the XSS and privilege-escalation issues.

Share:
Broadcom Patches VMware Aria Operations Flaws Enabling RCE During Support-Assisted Migrations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Feb 25, 20263mo ago

CVE-2026-22719 vulnerability record is published

On 2026-02-25, a public vulnerability record for CVE-2026-22719 described the unauthenticated command injection flaw in VMware Aria Operations as leading to arbitrary command execution and possible remote code execution during support-assisted migration. The record pointed users to Broadcom's fixed-version matrix and workaround guidance.

Feb 24, 20263mo ago

Canadian Centre for Cyber Security issues alert on VMware advisory

On 2026-02-24, the Canadian Centre for Cyber Security published alert AV26-162 referencing VMSA-2026-0001 and warning that versions prior to Aria Operations 8.18.6 and Cloud Foundation/vSphere Foundation 9.0.2.0 were affected. It urged administrators to review the advisory and apply the necessary updates.

Broadcom releases patches for affected VMware Aria and foundation products

Broadcom released fixes for the disclosed flaws, including Aria Operations 8.18.6 and VMware Cloud Foundation and vSphere Foundation 9.0.2.0. The advisory noted only a limited workaround for CVE-2026-22719, increasing the need to apply updates for the remaining issues.

Broadcom discloses VMware Aria Operations vulnerabilities in VMSA-2026-0001

On 2026-02-24, Broadcom published security advisory VMSA-2026-0001 covering three vulnerabilities in VMware Aria Operations and related VMware Cloud Foundation and vSphere Foundation products. The issues were tracked as CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721, including command injection, stored XSS, and privilege escalation impacts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Broadcom Patches VMware Aria Operations Flaws Enabling RCE During Support-Assisted Migrations | Mallory