VMware Aria Operations Bug Exploited, Cloud Resources at Risk

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A high-severity command injection vulnerability (CVE-2026-22719, CVSS 8.1) in VMware Aria Operations has been added to CISA's Known Exploited Vulnerabilities catalog. The flaw requires no authentication and can grant root access during a product migration window, potentially exposing an attacker to an organization's entire virtual infrastructure including credentials, network topology, and monitoring data. Broadcom has acknowledged reports of in-the-wild exploitation and urges customers to patch to version 8.18.6 or apply a workaround immediately. Security experts warn that compromising a cloud management platform like Aria Operations gives attackers outsized access, noting that threat groups like Scattered Spider, Qilin, and Lazarus Group have previously targeted VMware management infrastructure.

4m read timeFrom darkreading.com
Post cover image

Sort: