INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

U.S. CISA Adds Qualcomm Broadcom VMware Aria Flaws

| 2026-03-04 08:56 CRITICAL HIGH
Executive Summary AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, Zimbra flaws, and others. These additions were made on March 4, 2026, with the most recent being Broadcom VMware Aria Operations Command Injection Vulnerability CVE-2026-21385, a high-severity memory corruption issue that could lead to remote code execution in vulnerable systems. The vulnerabilities have been identified by Google as part of its advisory and are expected to be actively exploited due to their CVSS scores ranging from 7.8 to 8.1.
Technical Mitigations AI-generated
* Implement a secure patching strategy for VMware Aria Operations to address the known exploited vulnerabilities (CVE-2026-22719, CVE-2026-21385) and ensure timely implementation by March 24, 2026. * Conduct vulnerability assessments and penetration testing on critical infrastructure to identify potential entry points for attackers exploiting the identified vulnerabilities. * Implement robust access controls and authentication mechanisms to prevent unauthorized access to VMware Aria Operations and other affected systems. * Regularly update and patch software components, including operating systems and applications, to ensure that known exploits are addressed before they can be used against the system.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-22721CVE-2026-22721 CVE-2026-22719CVE-2026-22719 CVE-2026-22720CVE-2026-22720 CVE-2026-21385CVE-2026-21385
Target & Sectors
Global Scope healthhealth
Incident Timeline
2026-02-02
Threat actors used a known exploited vulnerability in VMware Aria Operations to exploit the Qualcomm and Broadcom vulnerabilities.
organisation VMware Aria Operations
tactic Remote Code Execution
February 24, 2026
Threat actors used a known exploited vulnerability in Qualcomm and Broadcom to target VMware systems.
vulnerability CVSS score of 8.1
organisation CVSS
organisation VMware
February 24
Threat actors exploited vulnerabilities in Qualcomm and Broadcom processors to gain unauthorized access.
Mar 04, 2026
Threat actors exploited vulnerabilities in Qualcomm and Broadcom's VMware Aria Operations software to gain unauthorized access.
VMSA-2026-0001
Threat actors exploited a known vulnerability in VMware Aria Operations, which was patched on February 24, 2026.
vulnerability CVSS score of 8.1
organisation CVSS
organisation VMware
2026-03-04
Broadcom and U.S. CISA added the VMware Aria Operations Command Injection Vulnerability CVE-2026-22719 to their Known Exploited Vulnerabilities catalog, citing active exploitation in the wild.
infrastructure Windows
organisation CVSS
infrastructure 7.8
organisation Broadcom
organisation VMware Aria Operations
infrastructure Android
organisation Google
infrastructure 9.0.2
infrastructure 8.18.6
organisation VMware Cloud Foundation
organisation VMware vSphere Foundation
organisation each Aria Operations Virtual Appliance
organisation NOPASSWD
organisation BleepingComputer
organisation The Red Report 2026
March 24, 2026
Threat actors used a vulnerability in Qualcomm and Broadcom to target VMware Aria Operations.
attribution FCEB
attribution Federal Civilian Executive Branch
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
source_region United States
Tactical Metrics
Metrics
infrastructure
​Windows
Affected Product
Metrics
infrastructure
​7.8
Software Version
Metrics
infrastructure
​Android
Affected Product
Metrics
infrastructure
​9.0.2
Software Version
Metrics
infrastructure
​8.18.6
Software Version