VMware Aria Operations Unauthenticated Command Injection RCE (CVE-2026-22719) — Threadlinqs Intelligence
As of 2026-05-30, VMware Aria Operations Unauthenticated Command Injection RCE (CVE-2026-22719) is a critical-severity vulnerability threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0178 · Severity: CRITICAL · CVSS: 8.1 · Status: MONITORING · Category: VULNERABILITY
Attribution: N/A · UNKNOWN
Critical command injection vulnerability in VMware Aria Operations (CVE-2026-22719) allows unauthenticated remote code execution during support-assisted product migration. Added to CISA KEV on March
CVE-2026-22719 is a command injection vulnerability (CWE-77) in Broadcom VMware Aria Operations, formerly known as vRealize Operations (vROps). The flaw resides in the product migration workflow and allows an unauthenticated attacker with network access to inject malicious commands into the migration process. These commands are then executed by the underlying Linux system with the privileges of the Aria Operations service, potentially achieving full remote code execution.
The vulnerability is exploitable while a support-assisted product migration is in progress, which is why the CVSS Attack Complexity is rated High (AC:H). This means systems are not continuously vulnerable but the risk spikes during migration windows. Despite this constraint, CISA confirmed active exploitation in the wild and added CVE-2026-22719 to the Known Exploited Vulnerabilities catalog on March 3, 2026, mandating federal remediation by March 24, 2026.
Broadcom disclosed and patched the vulnerability on February 24, 2026 as part of advisory VMSA-2026-0001, which also addresses two companion vulnerabilities: CVE-2026-22720, a stored cross-site scripting flaw (CVSS 8.0) allowing script injection via custom benchmarks, and CVE-2026-22721, a privilege escalation vulnerability (CVSS 6.2) enabling administrative access from vCenter.
VMware Aria Operations is a widely deployed enterprise IT operations management platform used to monitor and optimize virtualized environments including VMware vSphere, vSAN, and NSX. Organizations running affected versions in cloud and on-premises environments face significant risk — a compromised Aria Operations instance provides deep visibility into and potential control over the entire virtualized infrastructure, including hypervisors, virtual machines, network configurations, and storage.
The attack surface is particularly concerning because Aria Operations management interfaces are often accessible within management networks, and in some deployment configurations may be exposed to broader network segments. Exploitation during a migration window could allow an attacker to establish persistence, pivot to connected vCenter and ESXi hosts, access sensitive operational data, or disrupt monitoring capabilities to mask further intrusion activity.
Broadcom acknowledged reports of potential exploitation but stated they cannot independently confirm their validity. No public proof-of-concept exploit code has been released, and specific threat actor attribution remains unknown. The exploitation activity was sufficient for CISA to mandate emergency patching across all Federal Civilian Executive Branch agencies.
For organizations unable to immediately patch, Broadcom provides a temporary workaround shell script (aria-ops-rce-workaround.sh) that must be executed as root on each Aria Operations Virtual Appliance node. This script disables the migration components most likely to be abused during an attack. The workaround only addresses CVE-2026-22719 and does not mitigate CVE-2026-22720 or CVE-2026-22721.
---
**Revalidated on 2026-03-12**
As of March 12, 2026, CVE-2026-22719 remains under active exploitation with the CISA KEV remediation deadline (March 24, 2026) now only 12 days away. Broadcom updated advisory VMSA-2026-0001 to version 1.1 on March 3, 2026, acknowledging reports of potential wild exploitation while noting they cannot independently confirm validity. CISA's addition of CVE-2026-22719 to the KEV catalog on the same date represents the strongest US government signal that exploitation has been observed against real targets. The Canadian Centre for Cyber Security followed with an updated advisory (AV26-162).
The vulnerability's threat profile is amplified by the strategic value of VMware Aria Operations as an infrastructure monitoring platform. Successful exploitation grants attackers access to credentials, network topology, and monitoring data for every system the platform manages, creating a high-value pivot point into
Target sectors: government, financial, healthcare, technology, telecommunications, energy, defense, education, manufacturing
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-22719, T1595, T1592, T1190, T1059, T1203, T1505, T1136, T1068, T1070, T1036