Executive brief
Broadcom VMware Aria Operations, a platform used by IT teams to monitor and manage virtualized infrastructure, contains a critical security flaw. An attacker can exploit this vulnerability to take full control of the system and execute unauthorized commands while the software is undergoing a support-assisted migration. This vulnerability is known to be actively exploited in the wild, posing a significant risk of data theft or operational disruption.
Technical details
A command injection vulnerability (CWE-77) exists in VMware Aria Operations (formerly vRealize Operations) due to improper neutralization of special elements. An unauthenticated attacker can exploit this flaw over the network to execute arbitrary commands with high privileges, leading to full remote code execution (RCE). The attack surface is specifically exposed while a support-assisted product migration is in progress. While the attack complexity is rated as high, the vulnerability is listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Patches are available in Aria Operations 8.18.6 and corresponding versions of bundled products like VMware Cloud Foundation.
Affected products
- Broadcom Aria Operations 8.0 before 8.18.6
- Broadcom Cloud Foundation 4.0 before 5.2.3, 9.0 before 9.0.2.0
- Broadcom Telco Cloud Infrastructure 2.2 through 3.0
- Broadcom Telco Cloud Platform 4.0 through 5.1
Timeline
- 2026-02-25: disclosed: Initial disclosure by VMware/Broadcom
- 2026-02-25: patched: Patches released in Aria Operations 8.18.6
- 2026-03-03: kev added: Added to CISA KEV catalog due to active exploitation
- 2026-03-03: exploited