Broadcom published security advisory VMSA-2026-0001 on February 24, 2026, revealing three vulnerabilities in VMware Aria Operations that may enable attackers to run unauthorized commands remotely.
VMwareAria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure have flaws, but patches are now available for all affected versions.
The most critical flaw, tracked as CVE-2026-22719, is a command injection vulnerability with a CVSSv3 score of 8.1. The second vulnerability, CVE-2026-22720, is a stored cross-site scripting (XSS) flaw scored at 8.0. The third flaw, CVE-2026-22721, is a privilege escalation vulnerability with a CVSSv3 score of 6.2.
CVE ID
CVSS Score
Severity
Vulnerability Type
Attack Vector
CVE-2026-22719
8.1
Important
Command Injection / RCE
Network (Unauthenticated)
CVE-2026-22720
8.0
Important
Stored Cross-Site Scripting
Network (Low Privileges)
CVE-2026-22721
6.2
Moderate
Privilege Escalation
Network (High Privileges)
Affected Products & Fixes
Product
Affected Version
Fixed Version
VMware Aria Operations
8.x
8.18.6
VMware Cloud Foundation (VCF Operations)
9.x.x.x
9.0.2.0
VMware Cloud Foundation (Aria Operations)
5.x, 4.x
KB92148
VMware Telco Cloud Platform
5.x, 4.x
KB428241
VMware Telco Cloud Infrastructure
3.x, 2.x
KB428241
Broadcom urges administrators to apply patches right away. Organizations using VMware Aria Operations should prioritize upgrading to the listed fixed versions.
Broadcom reported that Sven Nobis and Lorin Lehawany from ERNW Enno Rey Netzwerke GmbH discovered this vulnerability. All three were privately shared with Broadcom prior to public disclosure.