VMware Aria Operations flaws could enable remote attacks

VMware Aria Operations flaws could enable remote attacks

VMware Aria Operations flaws could enable remote attacks

Pierluigi Paganini
February 24, 2026

Broadcom patched multiple VMware Aria Operations flaws, including high-severity issues that could enable remote code execution.

Broadcom has released security updates to address multiple vulnerabilities affecting VMware Aria Operations.

VMware Aria Operations is an IT operations management platform that helps organizations monitor and optimize virtual, cloud, and hybrid environments. It provides performance monitoring, capacity planning, automated alerting, and cost analysis, giving IT teams greater visibility and control over infrastructure to ensure efficiency, reliability, and compliance.

The most severe of the flaws is a command injection vulnerability, tracked as CVE-2026-22719 (CVSS 8.1), which an unauthenticated attacker can exploit remotely.

“A malicious unauthenticated actor may exploit this issue to…