Threat reportVulnerabilityTL-2026-1915
VMware Aria Operations Vulnerabilities — CVE-2026-22719 Command Injection (Active Exploitation), CVE-2026-22720 Stored XSS, CVE-2026-22721 Privilege Escalation
VMware Aria Operations Vulnerabilities (TL-2026-1915), also tracked as VMSA-2026-0001, is a high-severity software vulnerability scored CVSS 9, first published 2026-02-24. It has no confirmed attribution, affects Broadcom (VMware) Aria Operations, references 3 CVEs (CVE-2026-22719, CVE-2026-22720, CVE-2026-22721), maps to 18 MITRE ATT&CK techniques (T1021, T1059, T1071), and is covered by 9 detection rules and 2 indicators of compromise.
- CVSS
- 9/10High
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 2Indicators of compromise
Key facts for TL-2026-1915
- Threat ID
- TL-2026-1915
- Also known as
- VMSA-2026-0001, VMSA-2025-0015
- Severity
- HIGH
- CVSS
- 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, health, telecoms, finance, enterprise, education, technology
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 2
How VMware Aria Operations Vulnerabilities works
Three critical vulnerabilities disclosed in VMware Aria Operations (formerly vRealize Operations) affecting versions 8.x prior to 8.18.6, with downstream impact on VMware Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. CVE-2026-22719 is an unauthenticated command injection vulnerability enabling remote code execution during support-assisted product migration — CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on March 3, 2026, confirming active exploitation in the wild. CVE-2026-22720 allows stored cross-site scripting via custom benchmark injection (NVD CVSS 9.0). CVE-2026-22721 enables privilege escalation from vCenter user to Aria administrator with documented credential theft and cross-environment lateral movement capabilities via man-in-the-middle attacks on integration endpoints.
VMware Aria Operations (formerly vRealize Operations) is a centralized monitoring and operations management platform used across enterprise VMware environments. On February 24, 2026, Broadcom released VMSA-2026-0001 disclosing three distinct vulnerabilities discovered by independent security researchers that collectively expose Aria Operations deployments to remote code execution, cross-site scripting, and privilege escalation attacks.
CVE-2026-22719 (CVSS 8.1, CWE-77) is a command injection vulnerability in the vmware-casa migration service during support-assisted product migration. An unauthenticated attacker with network access can inject arbitrary operating system commands through unsanitized input to the migration workflow. The vulnerable code path involves a sudoers entry granting NOPASSWD execution of /usr/lib/vmware-casa/bin/vmware-casa-workflow.sh as root. CISA added this CVE to the Known Exploited Vulnerabilities catalog on March 3, 2026, with a federal remediation deadline of March 24, 2026. Broadcom acknowledged reports of exploitation but stated it could not independently confirm their validity. Public honeypot data showed a slight increase in scanning traffic beginning March 1, 2026, primarily targeting Europe and North America. No specific threat actor group has been publicly attributed, and no public proof-of-concept exploit code has been released.
CVE-2026-22720 (CVSS 8.0 by Broadcom / 9.0 by NVD, CWE-79) is a stored cross-site scripting vulnerability discovered by Tobias Anders of Deutsche Telekom Security GmbH. An authenticated attacker with privileges to create custom benchmarks can inject persistent JavaScript into benchmark content. When an administrator views that benchmark, the injected script executes in the admin's session context, enabling privilege transference through the UI. NVD's higher score reflects the possibility of scope change — the injected script could pivot to other browser-accessible resources beyond the Aria Operations application. No workaround exists; only patching remediates this vulnerability.
CVE-2026-22721 (CVSS 6.2 by Broadcom / 7.2 by NVD, CWE-269) is a privilege escalation vulnerability discovered by Sven Nobis and Lorin Lehawany of ERNW Enno Rey Netzwerke GmbH, disclosed through responsible disclosure starting July 17, 2025. The root cause is improper privilege management — VMware Aria Operations, by default configuration, maps vCenter users to the PowerUser role, providing extensive administrative capabilities within Aria without visibility in the Aria UI. ERNW documented two escalation paths: (1) authentication source manipulation — a PowerUser can add a rogue authentication source under their control and create an administrative user granting full Aria access; (2) credential theft via integrations — by abusing the Validate Connection feature with socat/ncat man-in-the-middle techniques, attackers can extract stored credentials for vCenter, VMware Identity Manager (VIDM), and VMware Cloud Director (VCD), then use them for lateral movement across the enterprise. As ERNW notes: 'An insignificant vCenter user in a development environment can take over all other vCenters in a complex corporate environment.' Tasks initiated from Aria are not visible in VCD, providing stealth for attacker actions.
In response to these vulnerabilities and the confirmed active exploitation of CVE-2026-22719, Broadcom released IDPS signature updates for VMware vDefend (formerly NSX) — signatures 1150806 and 1150807 for CVE-2026-22719, 1150485 for CVE-2026-22720, and 1150808 for CVE-2026-22721. The vDefend Security Services Platform 5.2 announcement on August 6, 2026, further documented on-premises malware prevention, AI-assisted security operations, and air-gapped support capabilities that enhance detection of such exploit attempts.
MITRE ATT&CK techniques used in TL-2026-1915
Lateral Movement
T1021 Remote Services; T1550 Use Alternate Authentication Material
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Command and Control
T1071 Application Layer Protocol
Persistence
Discovery
T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery
Initial Access
T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
Impact
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
Affected products and versions in VMware Aria Operations Vulnerabilities
- Broadcom (VMware) — Aria Operations
Vulnerable versions: 8.x < 8.18.6
Fixed in: 8.18.6 - Broadcom (VMware) — Cloud Foundation Operations
Vulnerable versions: 9.x.x.x < 9.0.2.0; 5.x < 5.2.3; 4.x < 5.2.3
Fixed in: 9.0.2.0; 5.2.3 - Broadcom (VMware) — vSphere Foundation
Vulnerable versions: 9.x.x.x < 9.0.2.0
Fixed in: 9.0.2.0 - Broadcom (VMware) — Telco Cloud Platform
Vulnerable versions: 5.x < 5.2.3; 4.x < 5.2.3; 2.x < 5.2.3
Fixed in: 5.2.3 per KB428241 - Broadcom (VMware) — Telco Cloud Infrastructure
Vulnerable versions: 3.x < 5.2.3; 2.x < 5.2.3
Fixed in: 5.2.3 per KB428241 - Broadcom (VMware) — vDefend Security Services Platform
Fixed in: 5.2 (IDPS signatures 1150806, 1150807, 1150485, 1150808)
Remediation for VMware Aria Operations Vulnerabilities
Patches
- VMware Aria Operations 8.18.6
- VMware Cloud Foundation 9.0.2.0
- VMware Cloud Foundation 5.2.3
- VMware Telco Cloud Platform per KB428241
- VMware Telco Cloud Infrastructure per KB428241
Immediate actions
- Upgrade VMware Aria Operations to version 8.18.6 or later
- Upgrade VMware Cloud Foundation to 9.0.2.0 (9.x) or 5.2.3 (5.x/4.x)
- Apply Telco Cloud patches per Broadcom KB428241 for Telco Cloud Platform/Infrastructure
- If patching is delayed, apply the aria-ops-rce-workaround.sh script from KB430349 to disable the vulnerable migration service
- Disable the 'Allow vCenter users to log in' setting in Aria Operations global settings if vCenter user access is not strictly required
Workarounds
- CVE-2026-22719: Deploy aria-ops-rce-workaround.sh (KB430349) — removes migration service script and NOPASSWD sudoers entry
- CVE-2026-22720: No workaround exists — restrict benchmark creation privileges to fully trusted accounts only
- CVE-2026-22721: Disable vCenter login feature in Aria Operations global settings
Longer-term hardening
- Restrict network-level access to Aria Operations management interfaces to trusted IP ranges
- Review all integrated credentials in Aria — assume any stored credential could be extracted by a lower-privileged vCenter admin
- Monitor Aria for changes to authentication sources and integration configurations as signs of tampering
- Assess network segmentation — Aria's VM management capabilities can bypass restrictions on direct vCenter/VCD administrative access
- Implement behavioral detection rules for anomalous child process spawning from Aria Operations processes
CVEs associated with VMware Aria Operations Vulnerabilities
Weaknesses (CWE) in VMware Aria Operations Vulnerabilities
Timeline of VMware Aria Operations Vulnerabilities
- ERNW researchers Sven Nobis and Lorin Lehawany responsibly disclosed privilege escalation vulnerabilities (CVE-2026-22721 and CVE-2025-41245) to Broadcom/VMware
- Broadcom released VMSA-2025-0015 patching CVE-2025-41245 (credential ownership issue in Aria Operations 8.18.x only)
- Broadcom released Aria Operations 8.18.6 and workaround script aria-ops-rce-workaround.sh (KB430349) for CVE-2026-22719 migration service command injection
- Broadcom published VMSA-2026-0001 disclosing CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721 with patches for Aria Operations 8.18.6 and Cloud Foundation 9.0.2.0
- Public honeypot data detected increased scanning traffic targeting Europe and North America, attributed to potential CVE-2026-22719 reconnaissance activity
- Broadcom updated VMSA-2026-0001.1 acknowledging reports of potential exploitation of CVE-2026-22719 in the wild, while stating inability to independently confirm validity
- CISA added CVE-2026-22719 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild; federal agencies required to remediate by March 24, 2026
- ERNW published full research paper detailing CVE-2026-22721 privilege escalation and credential theft attack chain including socat/ncat MITM techniques
- CISA-ADP added SSVC data to CVE-2026-22719 confirming exploitation: active, automatable: no, technical impact: total
- Broadcom announced vDefend SSP 5.2 with enhanced security capabilities and IDPS signatures detecting exploitation of CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721
Sources cited for VMware Aria Operations Vulnerabilities
- VMSA-2026-0001: VMware Aria Operations Vulnerabilities (Broadcom Security Advisory)
- CVE-2026-22719 — NVD Detail (Command Injection)
- CVE-2026-22720 — NVD Detail (Stored XSS)
- CVE-2026-22721 — NVD Detail (Privilege Escalation)
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-22719
- ERNW Insinuator: Vulnerabilities in Broadcom VMware Aria Operations (Full Research Paper)
- Broadcom KB430349: Workaround Script for CVE-2026-22719
- Aria Operations 8.18.6 Release Notes
- df00tech: CVE-2026-22719 SIGMA/KQL/SPL Detection Rules
- Broadcom IDPS Signature Update for CVE-2026-22719 (KB437118)
- vDefend SSP 5.2: For the Frontier AI Era (VMware Security Blog)
Detection coverage for TL-2026-1915
As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1915 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.