<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Aria-Operations — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/aria-operations/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 25 Feb 2026 15:21:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/aria-operations/feed.xml" rel="self" type="application/rss+xml"/><item><title>VMware Aria Operations Vulnerabilities Allow Remote Code Execution and Privilege Escalation</title><link>https://feed.craftedsignal.io/briefs/2026-02-vmware-aria-rce/</link><pubDate>Wed, 25 Feb 2026 15:21:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-02-vmware-aria-rce/</guid><description>Multiple vulnerabilities in VMware Aria Operations, Cloud Foundation, and Telco Cloud Platform/Infrastructure could allow unauthenticated remote code execution (CVE-2026-22719) and privilege escalation (CVE-2026-22720, CVE-2026-22721).</description><content:encoded>&lt;p>Broadcom released an advisory in February 2026 addressing three vulnerabilities in VMware Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure. CVE-2026-22719 (CVSS 8.1) is a command injection vulnerability in Aria Operations that can lead to RCE if exploited during a support-assisted product migration. CVE-2026-22720 (CVSS 8.0) is a cross-site scripting vulnerability where a malicious actor with privileges to create custom benchmarks may be able to inject…&lt;/p>
</content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vmware</category><category>aria-operations</category><category>rce</category><category>privilege-escalation</category></item></channel></rss>