# VMware Aria Operations Vulnerabilities — CVE-2026-22719 Command Injection (Active Exploitation), CVE-2026-22720 Stored XSS, CVE-2026-22721 Privilege Escalation

> Three critical vulnerabilities disclosed in VMware Aria Operations (formerly vRealize Operations) affecting versions 8.x prior to 8.18.6, with downstream impact on VMware Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. CVE-2026-22719 is an unauthenticated command injection vulnerability enabling remote code execution during support-assisted product migration — CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on March 3, 2026, confirming active exploitation in the wild. CVE-2026-22720 allows stored cross-site scripting via custom benchmark injection (NVD CVSS 9.0). CVE-2026-22721 enables privilege escalation from vCenter user to Aria administrator with documented credential theft and cross-environment lateral movement capabilities via man-in-the-middle attacks on integration endpoints.

- **Published:** 2026-02-24T00:00:00Z
- **Last reviewed:** 2026-02-24T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1915
- **ID:** TL-2026-1915
- **Severity:** HIGH (CVSS 9)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 2 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-22719, CVE-2026-22720, CVE-2026-22721

## Description

VMware Aria Operations (formerly vRealize Operations) is a centralized monitoring and operations management platform used across enterprise VMware environments. On February 24, 2026, Broadcom released VMSA-2026-0001 disclosing three distinct vulnerabilities discovered by independent security researchers that collectively expose Aria Operations deployments to remote code execution, cross-site scripting, and privilege escalation attacks.

CVE-2026-22719 (CVSS 8.1, CWE-77) is a command injection vulnerability in the vmware-casa migration service during support-assisted product migration. An unauthenticated attacker with network access can inject arbitrary operating system commands through unsanitized input to the migration workflow. The vulnerable code path involves a sudoers entry granting NOPASSWD execution of /usr/lib/vmware-casa/bin/vmware-casa-workflow.sh as root. CISA added this CVE to the Known Exploited Vulnerabilities catalog on March 3, 2026, with a federal remediation deadline of March 24, 2026. Broadcom acknowledged reports of exploitation but stated it could not independently confirm their validity. Public honeypot data showed a slight increase in scanning traffic beginning March 1, 2026, primarily targeting Europe and North America. No specific threat actor group has been publicly attributed, and no public proof-of-concept exploit code has been released.

CVE-2026-22720 (CVSS 8.0 by Broadcom / 9.0 by NVD, CWE-79) is a stored cross-site scripting vulnerability discovered by Tobias Anders of Deutsche Telekom Security GmbH. An authenticated attacker with privileges to create custom benchmarks can inject persistent JavaScript into benchmark content. When an administrator views that benchmark, the injected script executes in the admin's session context, enabling privilege transference through the UI. NVD's higher score reflects the possibility of scope change — the injected script could pivot to other browser-accessible resources beyond the Aria Operations application. No workaround exists; only patching remediates this vulnerability.

CVE-2026-22721 (CVSS 6.2 by Broadcom / 7.2 by NVD, CWE-269) is a privilege escalation vulnerability discovered by Sven Nobis and Lorin Lehawany of ERNW Enno Rey Netzwerke GmbH, disclosed through responsible disclosure starting July 17, 2025. The root cause is improper privilege management — VMware Aria Operations, by default configuration, maps vCenter users to the PowerUser role, providing extensive administrative capabilities within Aria without visibility in the Aria UI. ERNW documented two escalation paths: (1) authentication source manipulation — a PowerUser can add a rogue authentication source under their control and create an administrative user granting full Aria access; (2) credential theft via integrations — by abusing the Validate Connection feature with socat/ncat man-in-the-middle techniques, attackers can extract stored credentials for vCenter, VMware Identity Manager (VIDM), and VMware Cloud Director (VCD), then use them for lateral movement across the enterprise. As ERNW notes: 'An insignificant vCenter user in a development environment can take over all other vCenters in a complex corporate environment.' Tasks initiated from Aria are not visible in VCD, providing stealth for attacker actions.

In response to these vulnerabilities and the confirmed active exploitation of CVE-2026-22719, Broadcom released IDPS signature updates for VMware vDefend (formerly NSX) — signatures 1150806 and 1150807 for CVE-2026-22719, 1150485 for CVE-2026-22720, and 1150808 for CVE-2026-22721. The vDefend Security Services Platform 5.2 announcement on August 6, 2026, further documented on-premises malware prevention, AI-assisted security operations, and air-gapped support capabilities that enhance detection of such exploit attempts.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1078 Valid Accounts
- T1552 Unsecured Credentials
- T1557 Adversary-in-the-Middle
- T1528 Steal Application Access Token
- T1082 System Information Discovery
- T1087 Account Discovery
- T1518 Software Discovery
- T1550 Use Alternate Authentication Material
- T1021 Remote Services
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1567 Exfiltration Over Web Service
- T1489 Service Stop
- T1583 Acquire Infrastructure
- T1595 Active Scanning

## Sources

- [VMSA-2026-0001: VMware Aria Operations Vulnerabilities (Broadcom Security Advisory)](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947)
- [CVE-2026-22719 — NVD Detail (Command Injection)](https://nvd.nist.gov/vuln/detail/CVE-2026-22719)
- [CVE-2026-22720 — NVD Detail (Stored XSS)](https://nvd.nist.gov/vuln/detail/CVE-2026-22720)
- [CVE-2026-22721 — NVD Detail (Privilege Escalation)](https://nvd.nist.gov/vuln/detail/CVE-2026-22721)
- [CISA Known Exploited Vulnerabilities Catalog — CVE-2026-22719](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [ERNW Insinuator: Vulnerabilities in Broadcom VMware Aria Operations (Full Research Paper)](https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-cve-2026-22721/)
- [Broadcom KB430349: Workaround Script for CVE-2026-22719](https://knowledge.broadcom.com/external/article/430349)
- [Aria Operations 8.18.6 Release Notes](https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.html)
- [df00tech: CVE-2026-22719 SIGMA/KQL/SPL Detection Rules](https://df00tech.com/detections/CVE-2026-22719)
- [Broadcom IDPS Signature Update for CVE-2026-22719 (KB437118)](https://knowledge.broadcom.com/external/article/437118/idps-signature-update-for-cve202622719-c.html)
- [vDefend SSP 5.2: For the Frontier AI Era (VMware Security Blog)](https://blogs.vmware.com/security/2026/08/vdefend-ssp-for-frontier-ai-era.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1915
