VMware has released patches for several vulnerabilities affecting its Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure products . The most serious of these vulnerabilities allows unauthenticated attackers to execute arbitrary commands on the underlying operating system , while another allows authorized users to gain administrator privileges.

The issues — CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721 — were privately reported to Broadcom and there is no evidence of exploitation so far. However, critical vulnerabilities in Aria Operations have been exploited in the past, and enterprise virtualization infrastructure has been targeted by state-sponsored hacking groups.
See also: SolarWinds Serv-U: Critical vulnerabilities allow root access
Broadcom, the parent company of VMware, is advising customers to upgrade to Aria Operations version 8.18.6 , as well as VMware Cloud Foundation (VCF) versions 5.2.3 or 9.0.2 . VMware Telco Cloud Platform and Telco Cloud Infrastructure are also affected because they include Aria Operations, the IT management component for private and multicloud environments.
See also: Hackers exploit Ivanti EPMM zero-days to take control of MDM servers
VMware: Command Execution and Privilege Escalation
Although CVE-2026-22719 is a vulnerability that could lead to remote code execution, it is rated as High rather than Critical because it can only be exploited when a support-assisted product migration is in progress. As a result, widespread exploitation is less likely.

The second vulnerability, CVE-2026-22720, is described as a stored cross-site scripting (XSS), also rated as high severity, with a CVSS score of 8.0. This vulnerability allows privileged attackers to create custom benchmarks in a deployment to inject persistent scripting that would perform administrative actions.
See also: Jenkins vulnerability exposes build environments to XSS attacks
The third vulnerability is a moderate risk issue, rated 6.2, that can be exploited if attackers gain privileges in vCenter that allow them to access Aria Operations. vCenter is the management platform for vSphere virtual environments, and this vulnerability is considered an escalation of privileges because it could lead to administrative privileges in Aria.
