{"id":11100,"date":"2026-03-04T10:04:20","date_gmt":"2026-03-04T10:04:20","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/04\/cisa-warns-of-vmware-aria-operations-vulnerability-exploited-in-attacks\/"},"modified":"2026-03-04T10:04:20","modified_gmt":"2026-03-04T10:04:20","slug":"cisa-warns-of-vmware-aria-operations-vulnerability-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/04\/cisa-warns-of-vmware-aria-operations-vulnerability-exploited-in-attacks\/","title":{"rendered":"CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks"},"content":{"rendered":"<p>    CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability affecting VMware Aria Operations has been added to the Known Exploited Vulnerabilities (KEV) catalog.<\/p>\n<p>Broadcom recently issued a security advisory detailing a flaw that allows<a href=\"https:\/\/cybersecuritynews.com\/fortisandbox-xss-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\"> unauthenticated attackers to execute arbitrary commands.<\/a><\/p>\n<p>Organizations are urged to implement mitigations or discontinue use of the product if a fix is not possible.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-vmware-aria-operations-vulnerability\"><strong>VMware Aria Operations Vulnerability<\/strong><\/h2>\n<p><a href=\"https:\/\/cybersecuritynews.com\/vmware-aria-vulnerabilities-rce-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">VMware Aria Operations<\/a>, formerly known as vRealize Operations (vROps), is an IT operations management platform that monitors, manages, and optimizes data centers and cloud environments.<\/p>\n<p>The newly added vulnerability involves a <a href=\"https:\/\/cybersecuritynews.com\/d-link-nas-command-injection-impact\/\" target=\"_blank\" rel=\"noreferrer noopener\">command injection flaw<\/a> that can lead to remote code execution (RCE) during support-assisted product migrations.<\/p>\n<p>Because this vulnerability does not require authentication, it poses a significant risk to affected organizations.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Description<\/th>\n<th>CVSS Score<\/th>\n<th>CWE<\/th>\n<th>Known Ransomware Use<\/th>\n<th>Added to KEV<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/cybersecuritynews.com\/vmware-aria-vulnerabilities-rce-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-22719<\/a><\/td>\n<td>VMware Aria Operations command injection allowing remote code execution.<\/td>\n<td>N\/A<\/td>\n<td>CWE-77<\/td>\n<td>Unknown<\/td>\n<td>March 3, 2026<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>An attacker who successfully exploits this flaw could gain <a href=\"https:\/\/cybersecuritynews.com\/password-managers-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">unauthorized access to the underlying system<\/a>, execute arbitrary commands, and potentially compromise the entire IT infrastructure.<\/p>\n<p>The issue was initially discovered and reported, leading Broadcom to release patches and mitigations.<\/p>\n<p>However, <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-22719\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA has now confirmed that active exploitation<\/a> is occurring in the wild, prompting its addition to the KEV catalog.<\/p>\n<p>While CISA has confirmed active exploitation, details regarding the specific threat actors or campaigns leveraging this vulnerability remain undisclosed. It is currently unknown if this flaw has been used in <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leveraging-employee-monitoring-and-simplehelp-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware attacks<\/a>.<\/p>\n<p>CISA\u2019s Binding Operational Directive (BOD) 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies address vulnerabilities listed in the KEV catalog within a specific timeframe.<\/p>\n<p>In this case, agencies have until March 24, 2026, to apply the necessary mitigations or discontinue use of the product if no mitigations are available.<\/p>\n<p>Organizations outside the federal government are also <a href=\"https:\/\/cybersecuritynews.com\/patching-vulnerabilities-faster-reduces-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">strongly encouraged to prioritize patching<\/a> <a href=\"https:\/\/cybersecuritynews.com\/patching-vulnerabilities-faster-reduces-risks\/\"><\/a>or applying vendor-recommended mitigations.<\/p>\n<p>Broadcom has provided instructions for mitigating the risk, and users should consult the official advisory for detailed guidance.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/vmware-aria-operations-vulnerability-2\/\">CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/vmware-aria-operations-vulnerability-2\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of VMware Aria Operations Vulnerability Exploited in Attacks A critical vulnerability affecting VMware Aria Operations has been added to the Known Exploited Vulnerabilities (KEV) catalog. Broadcom recently issued a security advisory detailing a flaw that allows unauthenticated attackers to execute arbitrary commands. Organizations are urged to implement mitigations or discontinue use of the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11100","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11100"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11100"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11100\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}