Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

YouTube monetization replace: What creators must know as ‘AI slop’ overwhelms the platform

March 4, 2026

The US Authorities May Compel Tencent to Divest from US Gaming Corporations for Nationwide Safety

March 4, 2026

Some NCBA buyers could also be pressured into money exit in Nedbank deal

March 4, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • YouTube monetization replace: What creators must know as ‘AI slop’ overwhelms the platform
  • The US Authorities May Compel Tencent to Divest from US Gaming Corporations for Nationwide Safety
  • Some NCBA buyers could also be pressured into money exit in Nedbank deal
  • Telus jacked up roaming charges and nobody seen for months
  • Korea’s Center East Publicity Is Now an SME Cashflow Downside, Not Only a Delivery Story – KoreaTechDesk
  • Car Tire Stress Sensors Allow Silent Monitoring
  • Nomba companions Quantity to let Nigerian retailers obtain kilos
  • CISA flags VMware Aria Operations RCE flaw as exploited in assaults
Wednesday, March 4
NextTech NewsNextTech News
Home - Global Tech Pulse - CISA flags VMware Aria Operations RCE flaw as exploited in assaults
Global Tech Pulse

CISA flags VMware Aria Operations RCE flaw as exploited in assaults

NextTechBy NextTechMarch 4, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
CISA flags VMware Aria Operations RCE flaw as exploited in assaults
Share
Facebook Twitter LinkedIn Pinterest Email


The U.S. Cybersecurity and Infrastructure Safety Company (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Identified Exploited Vulnerabilities catalog, flagging the flaw as exploited in assaults.

Broadcom additionally warned that it’s conscious of stories indicating the vulnerability is exploited however says it can not independently verify the claims.

VMware Aria Operations is an enterprise monitoring platform that helps organizations monitor the efficiency and well being of servers, networks, and cloud infrastructure.

The vulnerability was initially disclosed and patched on February 24, 2026, as a part of VMware’s VMSA-2026-0001 advisory, which was rated Necessary with a CVSS rating of 8.1.

The flaw has now been added to the CISA’s Identified Exploited Vulnerabilities (KEV) catalog, with the US cyber company requiring federal civilian businesses to deal with the problem by March 24, 2026.

In a latest replace to the advisory, Broadcom mentioned it’s conscious of stories indicating the vulnerability is exploited in assaults however can not verify the claims.

“Broadcom is conscious of stories of potential exploitation of CVE-2026-22719 within the wild, however we can not independently verify their validity,” states the up to date advisory.

Right now, no technical particulars about how the flaw could also be exploited have been publicly disclosed.

BleepingComputer contacted Broadcom with questions relating to the reported exercise, however has not acquired a response.

The command injection flaw

In accordance with Broadcom, CVE-2026-22719 is a command injection vulnerability that enables an unauthenticated attacker to execute arbitrary instructions on weak techniques.

“A malicious unauthenticated actor could exploit this difficulty to execute arbitrary instructions which can result in distant code execution in VMware Aria Operations whereas support-assisted product migration is in progress,” the advisory explains.

Broadcom launched safety patches on February 24 and in addition supplied a brief workaround for organizations unable to use the patches instantly.

The mitigation is a shell script named “aria-ops-rce-workaround.sh,” which have to be executed as root on every Aria Operations equipment node.

The script disables parts of the migration course of that could possibly be abused throughout exploitation, together with eradicating the “/usr/lib/vmware-casa/migration/vmware-casa-migration-service.sh” and the next sudoers entry that enables vmware-casa-workflow.sh to run as root and not using a password:


NOPASSWD: /usr/lib/vmware-casa/bin/vmware-casa-workflow.sh

Admins are suggested to use obtainable VMware Aria Operations safety patches or implement workarounds as quickly as doable, particularly if the flaw is being actively exploited in assaults.

tines

Malware is getting smarter. The Crimson Report 2026 reveals how new threats use math to detect sandboxes and conceal in plain sight.

Obtain our evaluation of 1.1 million malicious samples to uncover the highest 10 methods and see in case your safety stack is blinded.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the most recent breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s tendencies at present: learn extra, subscribe to our publication, and grow to be a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Seize the Amazon Fireplace TV Stick 4K Choose at its most cost-effective worth

March 4, 2026

AI and collaboration crucial for cyber professionals in 2026

March 3, 2026

What If a Photo voltaic Panel May Make Energy From Each Solar and Rain?

March 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

YouTube monetization replace: What creators must know as ‘AI slop’ overwhelms the platform

By NextTechMarch 4, 2026

As Google proprietor Alphabet invests closely in AI, YouTube is discouraging “mass-produced” content material enabled…

The US Authorities May Compel Tencent to Divest from US Gaming Corporations for Nationwide Safety

March 4, 2026

Some NCBA buyers could also be pressured into money exit in Nedbank deal

March 4, 2026
Top Trending

YouTube monetization replace: What creators must know as ‘AI slop’ overwhelms the platform

By NextTechMarch 4, 2026

As Google proprietor Alphabet invests closely in AI, YouTube is discouraging “mass-produced”…

The US Authorities May Compel Tencent to Divest from US Gaming Corporations for Nationwide Safety

By NextTechMarch 4, 2026

The Monetary Instances has revealed a paywalled report revealing that the US…

Some NCBA buyers could also be pressured into money exit in Nedbank deal

By NextTechMarch 4, 2026

Some Kenyan institutional buyers in NCBA Group, one in every of East…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!