CISA flags VMware Aria Operations RCE flaw as exploited in attacks
2026-03-04T20:02:50Z•167ecf91192967fd264d9f78b4ac28fd6b7880584f13363abddc53940fc5a09e
CVE-2026-22719AWS outageAkzoNobelAndroid patchesCISA Known Exploited VulnerabilitiesCyberStrikeAIFortinet FortiGateGoogle Chrome release cycleLexisNexisOAuth abusePWA credential theftQualcomm zero-dayUniversity of HawaiiVMware Aria Operationscompromised cPanel marketdata breachdrone strikesphishingransomwareremote code execution
What happened
Multiple high-impact security incidents and developments: CISA added a VMware Aria Operations remote code execution vulnerability (CVE-2026-22719) to its Known Exploited Vulnerabilities catalog after observed exploitation. Several organizations confirmed breaches or data theft (AkzoNobel U.S. site, LexisNexis, Cloud Imperium/Star Citizen, University of Hawaii Cancer Center ransomware). Google released Android updates addressing 129 vulnerabilities including an actively exploited Qualcomm display zero-day. Microsoft warned attackers are abusing OAuth error flows to bypass protections, while a P
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 167ecf91192967fd264d9f78b4ac28fd6b7880584f13363abddc53940fc5a09e
- Enrichment time
- 2026-03-04T20:02:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.