Threat reportVulnerabilityTL-2026-0178
VMware Aria Operations Unauthenticated Command Injection RCE (CVE-2026-22719)
VMware Aria Operations Unauthenticated Command Injection RCE (TL-2026-0178), also tracked as VMSA-2026-0001, is a critical-severity software vulnerability scored CVSS 8.1, first published 2026-03-06. It has no confirmed attribution, affects Broadcom VMware Aria Operations, references 1 CVE (CVE-2026-22719), maps to 18 MITRE ATT&CK techniques (T1005, T1016, T1021), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 8.1/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0178
- Threat ID
- TL-2026-0178
- Also known as
- VMSA-2026-0001
- Severity
- CRITICAL
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, telecommunications, energy, defense, education, manufacturing
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 15
How VMware Aria Operations Unauthenticated Command Injection RCE works
Critical command injection vulnerability in VMware Aria Operations (CVE-2026-22719) allows unauthenticated remote code execution during support-assisted product migration. Added to CISA KEV on March 3, 2026 with confirmed active exploitation. Affects Aria Operations 8.x/9.x, Cloud Foundation 4.x/5.x/9.x, and Telco Cloud products.
CVE-2026-22719 is a command injection vulnerability (CWE-77) in Broadcom VMware Aria Operations, formerly known as vRealize Operations (vROps). The flaw resides in the product migration workflow and allows an unauthenticated attacker with network access to inject malicious commands into the migration process. These commands are then executed by the underlying Linux system with the privileges of the Aria Operations service, potentially achieving full remote code execution.
The vulnerability is exploitable while a support-assisted product migration is in progress, which is why the CVSS Attack Complexity is rated High (AC:H). This means systems are not continuously vulnerable but the risk spikes during migration windows. Despite this constraint, CISA confirmed active exploitation in the wild and added CVE-2026-22719 to the Known Exploited Vulnerabilities catalog on March 3, 2026, mandating federal remediation by March 24, 2026.
Broadcom disclosed and patched the vulnerability on February 24, 2026 as part of advisory VMSA-2026-0001, which also addresses two companion vulnerabilities: CVE-2026-22720, a stored cross-site scripting flaw (CVSS 8.0) allowing script injection via custom benchmarks, and CVE-2026-22721, a privilege escalation vulnerability (CVSS 6.2) enabling administrative access from vCenter.
VMware Aria Operations is a widely deployed enterprise IT operations management platform used to monitor and optimize virtualized environments including VMware vSphere, vSAN, and NSX. Organizations running affected versions in cloud and on-premises environments face significant risk — a compromised Aria Operations instance provides deep visibility into and potential control over the entire virtualized infrastructure, including hypervisors, virtual machines, network configurations, and storage.
The attack surface is particularly concerning because Aria Operations management interfaces are often accessible within management networks, and in some deployment configurations may be exposed to broader network segments. Exploitation during a migration window could allow an attacker to establish persistence, pivot to connected vCenter and ESXi hosts, access sensitive operational data, or disrupt monitoring capabilities to mask further intrusion activity.
Broadcom acknowledged reports of potential exploitation but stated they cannot independently confirm their validity. No public proof-of-concept exploit code has been released, and specific threat actor attribution remains unknown. The exploitation activity was sufficient for CISA to mandate emergency patching across all Federal Civilian Executive Branch agencies.
For organizations unable to immediately patch, Broadcom provides a temporary workaround shell script (aria-ops-rce-workaround.sh) that must be executed as root on each Aria Operations Virtual Appliance node. This script disables the migration components most likely to be abused during an attack. The workaround only addresses CVE-2026-22719 and does not mitigate CVE-2026-22720 or CVE-2026-22721.
---
**Revalidated on 2026-03-12**
As of March 12, 2026, CVE-2026-22719 remains under active exploitation with the CISA KEV remediation deadline (March 24, 2026) now only 12 days away. Broadcom updated advisory VMSA-2026-0001 to version 1.1 on March 3, 2026, acknowledging reports of potential wild exploitation while noting they cannot independently confirm validity. CISA's addition of CVE-2026-22719 to the KEV catalog on the same date represents the strongest US government signal that exploitation has been observed against real targets. The Canadian Centre for Cyber Security followed with an updated advisory (AV26-162).
The vulnerability's threat profile is amplified by the strategic value of VMware Aria Operations as an infrastructure monitoring platform. Successful exploitation grants attackers access to credentials, network topology, and monitoring data for every system the platform manages, creating a high-value pivot point into vCenter, ESXi hypervisors, and broader virtualized environments. Dark Reading reporting identifies Scattered Spider, Qilin, and Lazarus Group as threat actors with documented campaigns targeting VMware management infrastructure, making unpatched Aria Operations instances prime targets for both ransomware affiliates and state-sponsored APTs.
No public proof-of-concept exploit code has surfaced as of this date, but the absence of a PoC should not reduce urgency given confirmed active exploitation. The attack complexity remains High (AC:H) because exploitation is only possible during support-assisted product migration windows, but security teams should recognize that migration events may be initiated by social engineering or insider threats. Detection coverage gaps are a significant concern: security teams frequently exclude infrastructure monitoring tools from endpoint detection, creating exploitable visibility blind spots.
The vulnerability reporter for CVE-2026-22719 remains unacknowledged (privately reported), while CVE-2026-22720 was credited to Tobias Anders of Deutsche Telekom Security GmbH and CVE-2026-22721 to Sven Nobis and Lorin Lehawany of ERNW Enno Rey Netzwerke GmbH. Scanner coverage is now available via Tenable Nessus plugin 300235 and Qualys QID 733801. Organizations must upgrade to Aria Operations 8.18.6 or VCF/vSF 9.0.2.0 before the March 24 deadline.
MITRE ATT&CK techniques used in TL-2026-0178
collection
discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
lateral-movement
T1021 Remote Services; T1210 Exploitation of Remote Services
defense-evasion
T1036 Masquerading; T1070 Indicator Removal
execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
persistence
T1136 Create Account; T1505 Server Software Component
initial-access
T1190 Exploit Public-Facing Application
impact
reconnaissance
Affected products and versions in VMware Aria Operations Unauthenticated Command Injection RCE
- Broadcom — VMware Aria Operations
Vulnerable versions: 8.0; 8.1; 8.2; 8.3; 8.4; 8.5; 8.6; 8.7; 8.8; 8.9
Fixed in: 8.18.6 - Broadcom — VMware Aria Operations
Vulnerable versions: 9.0; 9.0.1
Fixed in: 9.0.2 - Broadcom — VMware Cloud Foundation
Vulnerable versions: 9.0; 9.0.1; 9.0.2.0
Fixed in: 9.0.2.0 (Operations component update) - Broadcom — VMware Cloud Foundation
Vulnerable versions: 4.0; 4.1; 4.2; 4.3; 4.4; 4.5; 5.0; 5.1; 5.2; 5.2.1
Fixed in: Apply KB92148 - Broadcom — VMware Telco Cloud Platform
Vulnerable versions: 4.0; 4.1; 4.2; 4.3; 5.0; 5.1
Fixed in: Apply KB428241 - Broadcom — VMware Telco Cloud Infrastructure
Vulnerable versions: 2.2; 2.3; 2.4; 2.5; 3.0
Fixed in: Apply KB428241
Remediation for VMware Aria Operations Unauthenticated Command Injection RCE
Patches
- VMware Aria Operations 8.x: Upgrade to 8.18.6
- VMware Aria Operations 9.x: Upgrade to 9.0.2
- VMware Cloud Foundation 9.x: Upgrade to 9.0.2.0
- VMware Cloud Foundation 4.x/5.x: Apply KB92148
- VMware Telco Cloud Platform 4.x/5.x: Apply KB428241
- VMware Telco Cloud Infrastructure 2.x/3.x: Apply KB428241
Immediate actions
- Apply Broadcom patches: upgrade Aria Operations 8.x to 8.18.6 or 9.x to 9.0.2
- If patching is not immediately possible, download and execute aria-ops-rce-workaround.sh as root on every Aria Operations appliance node
- Restrict network access to Aria Operations management interfaces using ACLs and firewall rules
- Suspend all non-critical product migration activities until patches are applied
- Monitor Aria Operations nodes for anomalous process execution and command injection indicators
Workarounds
- Execute aria-ops-rce-workaround.sh as root on each Aria Operations Virtual Appliance node (disables vulnerable migration components)
- Note: workaround only addresses CVE-2026-22719, does NOT mitigate CVE-2026-22720 or CVE-2026-22721
- Workaround details in Broadcom KB430349
Longer-term hardening
- Implement Zero Trust network segmentation for all VMware management interfaces
- Deploy EDR with behavioral detection on Aria Operations appliance nodes
- Establish continuous vulnerability management for VMware infrastructure components
- Implement network monitoring for anomalous traffic to/from Aria Operations management ports (443, 8443)
- Review and harden VMware Cloud Foundation deployment configurations
- Conduct post-patch forensic review of Aria Operations nodes for signs of prior compromise
CVEs associated with VMware Aria Operations Unauthenticated Command Injection RCE
Weaknesses (CWE) in VMware Aria Operations Unauthenticated Command Injection RCE
Timeline of VMware Aria Operations Unauthenticated Command Injection RCE
- Broadcom publishes KB430349 with workaround script aria-ops-rce-workaround.sh for organizations unable to immediately patch
- Broadcom releases patches: Aria Operations 8.18.6 and 9.0.2, plus KB92148 and KB428241 for Cloud Foundation and Telco Cloud products
- Broadcom publishes VMSA-2026-0001 security advisory disclosing CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721 with patches and workaround script
- CVE-2026-22719 published in NVD with CVSS 8.1 High rating and CWE-77 classification
- Tenable releases Nessus plugin 300235 for detecting CVE-2026-22719 on vulnerable systems
- Canadian Centre for Cyber Security (CCCS) updates advisory AV26-162 to reflect active exploitation status of CVE-2026-22719 [Source: https://www.cyber.gc.ca/en/alerts-advisories/vmware-security-advisory-av26-162]
- CISA adds CVE-2026-22719 to Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-21385 (Qualcomm), setting mandatory FCEB remediation deadline of March 24, 2026 [Source: https://www.cisa.gov/news-events/alerts/2026/03/03/cisa-adds-two-known-exploited-vulnerabilities-catalog]
- Broadcom updates VMSA-2026-0001 to version 1.1, acknowledging reports of potential wild exploitation of CVE-2026-22719 but stating they cannot independently confirm validity [Source: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947]
- Broadcom acknowledges reports of potential exploitation of CVE-2026-22719 in the wild but states they cannot independently confirm validity
- CISA adds CVE-2026-22719 to Known Exploited Vulnerabilities catalog confirming active exploitation in the wild
- Qualys releases QID 733801 for enterprise vulnerability scanning detection of CVE-2026-22719 [Source: https://threatprotect.qualys.com/2026/03/04/vmware-aria-operations-vulnerability-added-to-cisa-known-exploited-vulnerabilities-catalog-cve-2026-22719/]
- NVD record for CVE-2026-22719 last modified with updated references and KEV status; wide security vendor coverage from BleepingComputer, The Hacker News, Dark Reading, SecurityWeek, SOCRadar, and Qualys [Source: https://nvd.nist.gov/vuln/detail/CVE-2026-22719]
- Qualys releases QID 733801 for detecting CVE-2026-22719 vulnerability in enterprise scanning
- Multiple security vendors and news outlets report on active exploitation: SecurityWeek, BleepingComputer, The Hacker News, Dark Reading, SOCRadar, Qualys
- Broadcom advisory VMSA-2026-0001.1 last updated date changes to March 11, 2026; advisory status remains OPEN indicating ongoing monitoring of exploitation activity [Source: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947]
- CISA mandatory remediation deadline for all Federal Civilian Executive Branch agencies
- As of 2026-05-29, CVE-2026-22719 (VMware Aria Operations RCE) remains in CISA KEV as actively exploited, with the Broadcom patch (VMSA-2026-0001; 8.18.6/9.0.2.0) and the past March 24 federal deadline being the resolution path. It is still active against unpatched systems but warrants MONITORING: no public PoC, mass-scanning surge, or successor CVE has emerged since the March 12 revalidation.
Sources cited for VMware Aria Operations Unauthenticated Command Injection RCE
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (March 3, 2026)
- VMSA-2026-0001 - Broadcom Security Advisory
- NVD - CVE-2026-22719
- Workaround Instructions for CVE-2026-22719 - Broadcom KB430349
- CISA Adds Actively Exploited VMware Aria Operations Flaw to KEV - The Hacker News
- CISA Flags VMware Aria Operations RCE Flaw as Exploited - BleepingComputer
- VMware Aria Operations Vulnerability Exploited in the Wild - SecurityWeek
- VMware Aria Operations Bug Exploited, Cloud Resources at Risk - Dark Reading
- CVE-2026-22719 SOCRadar Analysis
- VMware Aria Operations Vulnerability - Qualys ThreatPROTECT
- VMware Aria Operations Vulnerabilities Enable RCE - Diamatix
- Tenable CVE-2026-22719 - Plugin ID 300235
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-0178
As of 2026-03-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0178 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.