CISA has added the vulnerability CVE -2026-22719 , which affects VMware Aria Operations , to the List of Known Exploitable Vulnerabilities (KEV) , confirming its active exploitation by cybercriminals.

This critical command injection with a CVSS score of 8.1 allows unauthenticated attackers to execute arbitrary commands on the system. The addition to the KEV list is a clear indication that the vulnerability is not just a theoretical threat, but is actively used in real cyberattacks.
According to the advisory issued by Broadcom on February 24, 2026, the vulnerability, CVE-2026-22719, is located in the product migration functionality. A malicious unauthenticated attacker could exploit this issue to execute arbitrary commands, which could lead to remote code execution while the migration process is in progress.
See also: Google and iVerify reveal iPhone exploit kit
The vulnerability affects specific versions of VMware that are widely used in enterprise environments worldwide. VMware Cloud Foundation and VMware vSphere Foundation 9.xxx were patched in version 9.0.2.0, while VMware Aria Operations 8.x was in version 8.18.6.
Customers who are unable to immediately apply the security update can download and run a temporary script named “aria-ops-rce-workaround.sh” as root on each Aria Operations Virtual Appliance. This temporary measure provides a basic level of protection until the final fix is applied.

VMware Aria Operations: Other vulnerabilities and impact
Broadcom 's advisory addressed three critical vulnerabilities with CVSS scores ranging from 6.2 to 8.1 , creating a complex threat landscape. In addition to CVE-2026-22719 , it includes CVE-2026-22720 , a stored cross-site scripting vulnerability with a CVSS score of 8.0 , and CVE-2026-22721 , a privilege escalation vulnerability with a CVSS score of 6.2 that allows users with vCenter privileges to gain administrative access. Exploiting these vulnerabilities in combination could lead to a catastrophic breach of infrastructure.
See also: Chrome Vulnerability: Malicious Extensions and Gemini Panel
The impact is particularly severe in enterprise environments where VMware Aria Operations manages critical infrastructure.
Advanced protection and monitoring strategies
Beyond immediately applying security patches , organizations should adopt a layered security approach. Implementing advanced network and system monitoring can identify anomalous activity during migration processes. Administrators should create specific SIEM to monitor for unexpected command executions or unusual system behavior during migrations.

Implementing Zero Trust for administrative access is critical, including requiring multi-sign-on for all administrative functions and using privileged access accounts (PAM) to limit exposure. Additionally, regularly evaluating and auditing migration processes can reduce opportunities for exploitation.
See also: APT28 linked to MSHTML zero-day ahead of February Patch Tuesday
Federal agencies are asked to implement the fixes by March 24, 2026.The lack of details about how the vulnerability is being exploited and who is behind it makes preventive action even more imperative.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
