HomeUpdatesVMware fixes vulnerability in Aria Operations

VMware fixes vulnerability in Aria Operations

VMware has released patches for several vulnerabilities affecting its Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure products . The most serious of these vulnerabilities allows unauthenticated attackers to execute arbitrary commands on the underlying operating system , while another allows authorized users to gain administrator privileges.

VMware Aria Operations vulnerability

The issues — CVE-2026-22719, CVE-2026-22720, and CVE-2026-22721 — were privately reported to Broadcom and there is no evidence of exploitation so far. However, critical vulnerabilities in Aria Operations have been exploited in the past, and enterprise virtualization infrastructure has been targeted by state-sponsored hacking groups.

See also: SolarWinds Serv-U: Critical vulnerabilities allow root access

Broadcom, the parent company of VMware, is advising customers to upgrade to Aria Operations version 8.18.6 , as well as VMware Cloud Foundation (VCF) versions 5.2.3 or 9.0.2 . VMware Telco Cloud Platform and Telco Cloud Infrastructure are also affected because they include Aria Operations, the IT management component for private and multicloud environments.

See also: Hackers exploit Ivanti EPMM zero-days to take control of MDM servers

VMware: Command Execution and Privilege Escalation

Although CVE-2026-22719 is a vulnerability that could lead to remote code execution, it is rated as High rather than Critical because it can only be exploited when a support-assisted product migration is in progress. As a result, widespread exploitation is less likely.

VMware fixes vulnerability in Aria Operations

The second vulnerability, CVE-2026-22720, is described as a stored cross-site scripting (XSS), also rated as high severity, with a CVSS score of 8.0. This vulnerability allows privileged attackers to create custom benchmarks in a deployment to inject persistent scripting that would perform administrative actions.

See also: Jenkins vulnerability exposes build environments to XSS attacks

The third vulnerability is a moderate risk issue, rated 6.2, that can be exploited if attackers gain privileges in vCenter that allow them to access Aria Operations. vCenter is the management platform for vSphere virtual environments, and this vulnerability is considered an escalation of privileges because it could lead to administrative privileges in Aria.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS