Skip to content
VMware Aria Flaws Enable Attackers to Execute Remote Code

VMware Aria Flaws Enable Attackers to Execute Remote Code

Gbhackers • February 24, 2026

Broadcom has released security advisory VMSA-2026-0001 on February 24, 2026, disclosing three vulnerabilities in VMware Aria Operations that could allow attackers to execute arbitrary commands remotely.

The flaws affect VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure, and patches are now available for all impacted versions.

The most critical flaw, tracked as CVE-2026-22719, is a command injection vulnerability with a CVSSv3 score of 8.1.

A malicious unauthenticated actor can exploit this issue to execute arbitrary commands and achieve remote code execution (RCE) in VMware Aria Operations while a support-assisted product migration is in progress.

This makes it particularly dangerous as it requires no credentials to trigger. A workaround for this specific flaw is documented in Broadcom Knowledge Base article KB430349. ​

The second vulnerability, CVE-2026-22720, is a stored cross-site scripting (XSS) flaw scored at 8.0.

An attacker with privileges to create custom benchmarks can inject malicious scripts to perform unauthorized administrative actions within the Aria Operations interface.

This vulnerability was reported by Tobias Anders of Deutsche Telekom Security GmbH. ​

The third flaw, CVE-2026-22721, is a privilege escalation vulnerability with a CVSSv3 score of 6.2.

A malicious actor with existing privileges in vCenter can leverage this issue to gain full administrative access in VMware Aria Operations.

According to Broadcom , this vulnerability was discovered by Sven Nobis and Lorin Lehawany of ERNW Enno Rey Netzwerke GmbH. All three vulnerabilities were privately reported to Broadcom before public disclosure.

Affected Products & Fixes

Broadcom strongly recommends that administrators apply the available patches immediately. Organizations running VMware Aria Operations in any environment should prioritize upgrading to the fixed versions listed above.

The command injection flaw (CVE-2026-22719) poses the highest risk due to its unauthenticated remote exploitation potential, and a temporary workaround via KB430349 is available for environments where immediate patching is not feasible.

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Threat actors are rapidly weaponizing artificial intelligence to move from initial access to full domain…

Windows Management Instrumentation (WMI) is a critical utility built into the Windows operating system designed…

A massive data breach at business services giant Conduent has compromised the sensitive personal information…

Malicious NuGet packages posing as legitimate developer utilities are targeting ASP.NET projects to steal identity…

Anthropic has identified and exposed industrial-scale data extraction campaigns orchestrated by three major Chinese AI…

A Romanian national has pleaded guilty to charges related to unauthorized access and sale of…

Extracted Entities