Cyber Security News

Multiple VMware Aria Vulnerabilities Allow Remote Code Execution Attacks

Broadcom issued security advisory VMSA-2026-0001 on February 24, 2026, disclosing three vulnerabilities in VMware Aria Operations that pose risks, including remote code execution. Organizations using affected products should prioritize patching to mitigate potential exploits.

VMware Aria Operations, a key component in products like VMware Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure, faces command injection (CVE-2026-22719, CVSS 8.1), stored cross-site scripting (CVE-2026-22720, CVSS 8.0), and privilege escalation (CVE-2026-22721, CVSS 6.2) flaws.

The most critical issue, CVE-2026-22719, allows unauthenticated attackers to execute arbitrary commands during support-assisted product migrations, potentially leading to full remote code execution.

CVE-2026-22720 enables privileged users to create custom benchmarks to inject scripts for administrative actions, while CVE-2026-22721 lets vCenter users with access escalate to admin rights in Aria Operations. All issues fall under Important severity, with patches now available across impacted versions.

CVE IDDescription
CVE-2026-22719Stored XSS via custom benchmarks, allowing admin actions.
CVE-2026-22720Stored XSS via custom benchmarks allowing admin actions.
CVE-2026-22721Command injection vulnerability is exploitable by unauthenticated actors during migrations for RCE.

Affected Versions and Fixes

Impacted deployments span VMware Aria Operations 8.x and earlier bundles in Cloud Foundation 9.x/5.x/4.x, Telco Cloud Platform 5.x/4.x, and Telco Cloud Infrastructure 3.x/2.x.

A workaround exists for CVE-2026-22719 via KB430349, but none exists for the others, underscoring the urgency of upgrades. Release notes confirm fixes in versions like Aria Operations 8.18.6 and Cloud Foundation 9.0.2.0.

ProductComponentAffected VersionsFixed VersionWorkaround
VMware Cloud FoundationVMware vSphere Foundation / Operations9.x9.0.2.0 [techdocs.broadcom.com]KB430349 (CVE-2026-22719)
VMware Aria OperationsN/A8.x8.18.6 [techdocs.broadcom.com]KB430349 (CVE-2026-22719)
VMware Cloud FoundationVMware Aria Operations5.x, 4.xKB92148KB430349 (CVE-2026-22719)
VMware Telco Cloud PlatformVMware Aria Operations5.x, 4.xKB428241KB430349 (CVE-2026-22719)
VMware Telco Cloud InfrastructureVMware Aria Operations3.x, 2.xKB428241KB430349 (CVE-2026-22719)

Administrators must verify deployments against the matrix and apply updates promptly, as exploitation during migrations could compromise cloud operations. Credits go to reporters Tobias Anders (Deutsche Telekom Security), Sven Nobis, and Lorin Lehawany (ERNW).

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago