CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog

2026-03-04T22:37:02Z4fd244508f16b3491a678bb90ee7a626dc145b9a8a46fab1fca56634a18c7fee
CVE-2026-0628CVE-2026-20127CVE-2026-21385CVE-2026-21513CVE-2026-22719APT28Aeternum-blockchain-C2CISA-KEVChrome-WebViewCisco-SD-WANCyberStrikeAIFreePBXHavoc-C2MSHTMLOAuth-redirect-abuseQualcomm-AndroidStarkillerVMware-Ariaactive-exploitationmalicious-npmsupply-chainweb-shell

What happened

A cluster of high-impact threats and actively exploited vulnerabilities were reported across enterprise and consumer infrastructure. Key items include CISA adding VMware Aria Operations command-injection CVE-2026-22719 to the KEV catalog for active exploitation, a long-running, exploited Cisco SD‑WAN zero-day CVE-2026-20127 (CVSS 10.0) allowing unauthenticated admin access, and disclosures of other exploited/high-severity flaws (CVE-2026-21513 in MSHTML, CVE-2026-0628 in Chrome WebView, CVE-2026-21385 in a Qualcomm Android component). The feed also highlights multiple active campaigns and tool

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4fd244508f16b3491a678bb90ee7a626dc145b9a8a46fab1fca56634a18c7fee
Enrichment time
2026-03-04T22:37:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.