<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo" -->

---
title: VMware fixes command injection flaw in Aria Operations
description: Broadcom has released patches for three vulnerabilities in VMware Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. The...
canonical: https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: VMware fixes command injection flaw in Aria Operations | daily.dev
og:description: Broadcom has released patches for three vulnerabilities in VMware Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. The...
og:url: https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo
og:image: https://api.daily.dev/og/posts/Ue2MrJloo.png
og:image:alt: VMware fixes command injection flaw in Aria Operations
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# VMware fixes command injection flaw in Aria Operations

**[CSO Online](https://daily.dev/sources/csoonline)** · 2 min read · 0 upvotes · 0 comments

## Summary

Broadcom has released patches for three vulnerabilities in VMware Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. The most critical flaw (CVE-2026-22719) is an unauthenticated command injection vulnerability enabling remote code execution, though rated 'high' rather than 'critical' because exploitation requires an active support-assisted migration. A stored XSS flaw (CVE-2026-22720, CVSS 8.0) allows privilege escalation to admin via persistent scripting, and a moderate flaw (CVE-2026-22721, CVSS 6.2) enables privilege escalation through vCenter access. No in-the-wild exploitation has been observed, but similar past vulnerabilities attracted hundreds of thousands of attack attempts. Customers are advised to upgrade to Aria Operations 8.18.6 and VMware Cloud Foundation 5.2.3 or 9.0.2.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4136954/vmware-fixes-command-injection-flaw-in-aria-operations.html>

## Similar posts on daily.dev

- [VMware Aria Operations Bug Exploited, Cloud Resources at Risk](https://daily.dev/posts/vmware-aria-operations-bug-exploited-cloud-resources-at-risk-6wzhmakwc) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#vmware](https://daily.dev/tags/vmware)

[View this post on daily.dev](https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"VMware fixes command injection flaw in Aria Operations","url":"https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo"},"datePublished":"2026-02-25T01:06:19.007Z","dateModified":"2026-02-25T01:06:48.577Z","description":"Broadcom has released patches for three vulnerabilities in VMware Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. The...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/92b48403fe3709dcf8aaeaf8aa38daf3?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/92b48403fe3709dcf8aaeaf8aa38daf3?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/vmware-fixes-command-injection-flaw-in-aria-operations-ue2mrjloo","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,vmware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"VMware fixes command injection flaw in Aria Operations"}]}
```

