Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

VMware Aria Operations Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in VMware Aria Operations. This vulnerability allows a malicious, unauthenticated actor to execute arbitrary commands, potentially leading to remote code execution, while support-assisted product migration is in progress. The issue is present in VMware Aria Operations versions 8.18.x prior to 8.18.6 and 9.0.x prior to 9.0.1.

Impact

Exploitation of this vulnerability could result in unauthorized command execution, with the possibility of remote code execution on the affected system.

Remediation

To address this vulnerability, users can upgrade to VMware Aria Operations versions 8.18.6 or 9.0.2. For those using VMware Cloud Foundation, version 5.2.3 is available. Workaround instructions are also available for CVE-2026-22719.

Added: Feb 26, 2026, 12:50 AM
Updated: Mar 3, 2026, 6:11 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
10.0
exploitability
7.9
remediation
7.7
relevance
3.2
threat
8.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.