VMware’s Support-Assisted Migration Could Open an RCE Window
VMware Aria CVE-2026-22719 could expose a remote command-injection path during a support-assisted migration. CISA says attackers exploited it while organisations were changing platforms.
Broadcom’s VMSA-2026-0001 covers three vulnerabilities in VMware Aria Operations and VMware Cloud Foundation Operations. The most urgent is an unauthenticated command-injection flaw that can lead to remote code execution while a support-assisted product migration is in progress.
The same bulletin also fixes a stored cross-site scripting issue and a privilege-escalation path. They have different prerequisites and should not be collapsed into the exploited migration flaw.
Every vulnerability in VMSA-2026-0001
| Vulnerability | Impact and prerequisites | Status and remediation |
|---|---|---|
| CVE-2026-22719 | Command injection, CVSS 8.1. An unauthenticated attacker can execute arbitrary commands while a support-assisted migration is in progress. | CISA added it to KEV based on active exploitation. A workaround exists, but the fixed release is preferred. |
| CVE-2026-22720 | Stored cross-site scripting, CVSS 8.0. A user with benchmark-creation privileges can perform actions with administrator impact. | No exploitation confirmed in the advisory. Install the fixed release; no standalone workaround is listed. |
| CVE-2026-22721 | Privilege escalation, CVSS 6.2. An actor with vCenter privileges and access to Aria Operations can obtain administrator privileges. | No exploitation confirmed in the advisory. Install the fixed release. |
The dangerous condition may be temporary
The exploitability of the command-injection issue depends on a support-assisted migration being underway. That prerequisite reduces the number of continuously exposed systems, but it also creates a monitoring challenge. A short-lived administrative workflow can open a high-impact window precisely when teams are making configuration changes, moving data and expecting unusual platform activity.
Broadcom initially published the advisory on 24 February 2026 and updated it on 3 March. The company said it could not independently confirm reports of exploitation. CISA added the flaw to its KEV catalogue on 3 March based on evidence of active exploitation. Those statements are not contradictory: the vendor did not confirm the reports independently, while the government exploitation catalogue made its own determination.
Broadcom fixed the issues in VCF Operations 9.0.2.0 and Aria Operations 8.18.6, with additional product-specific guidance for VCF 4 and 5 and telco deployments.
What defenders should do
- Upgrade before beginning a migration. Do not open a support-assisted migration window on a vulnerable release.
- Use the official workaround only when immediate upgrading is impossible. Validate that the mitigation remains in place throughout the migration.
- Review recent migrations. Identify the precise start and end of every support-assisted migration and inspect activity during those windows.
- Hunt for command execution. Examine appliance logs, child processes, file writes, new accounts and outbound connections that cannot be explained by the migration procedure.
- Address all three CVEs. Review benchmark-creation privileges and vCenter-to-Aria trust relationships, not only the command-injection route.
- Preserve support records. Retain tickets, remote-session records and change plans so incident responders can separate authorised actions from attacker activity.
The BlackTree view
Migrations concentrate privileges, exceptions and uncertainty. That makes a temporary vulnerability condition no less serious. It can make the attacker harder to distinguish from the authorised work.
The safest sequence is to patch first, migrate second and preserve enough telemetry to prove what occurred between them. A successful move to the new platform does not establish that the old one was clean during the handover.
Sources and publication details
- Broadcom VMSA-2026-0001, initially published 24 February 2026, updated 3 March and last updated 11 March 2026. No publication times were provided.
- CISA notification adding the VMware flaw to KEV, published 3 March 2026 at 2:30 PM EST, equivalent to 20:30 CET.


