Today: 14 April 2026
Broadcom’s VMware Aria bug hits CISA exploited list, setting patch clock for agencies
4 March 2026
2 mins read

Broadcom’s VMware Aria bug hits CISA exploited list, setting patch clock for agencies

Washington—March 4, 2026, 11:04 EST

  • The U.S. Cybersecurity and Infrastructure Security Agency has placed Broadcom’s VMware Aria Operations vulnerability, tracked as CVE-2026-22719, on its catalog of exploited bugs, and gave federal agencies until March 24 to patch it.
  • Broadcom has heard about potential exploitation, though it hasn’t been able to verify the reports; patches and a workaround are up for grabs.
  • Broadcom is doubling down on VMware software, with an earnings release set for after the bell. The alert comes as the company shifts focus.

The U.S. Cybersecurity and Infrastructure Security Agency flagged a flaw in Broadcom’s VMware Aria Operations software, putting it on its Known Exploited Vulnerabilities list and giving federal civilian agencies until March 24 to patch the issue, according to a U.S. government vulnerability database entry.

This isn’t just hypothetical—the KEV list is CISA’s active catalog of vulnerabilities it says attackers are exploiting right now. For IT teams, the roster doesn’t just raise the stakes, it usually means they’ll have to patch much faster—often on a tighter schedule than just the public sector.

VMware Aria Operations helps enterprises keep tabs on their infrastructure, while Broadcom keeps steering VMware software further into private-cloud stacks. If attackers get through a flaw in these operational tools, they can end up inside systems powering everything from core business apps to telecom networks.

Broadcom flagged CVE-2026-22719 as a command-injection vulnerability—essentially, attackers might feed their own commands to the system and trigger remote code execution. That opens the door for malicious code to run from afar, if exploited. In a recent update, Broadcom said, “Broadcom is aware of reports of potential exploitation of CVE-2026-22719 in the wild, but we cannot independently confirm their validity.” Support Portal

Broadcom rolled out patches as well as a temporary workaround, pointing users to Aria Operations 8.18.6 and 9.0.2 for the fixed releases, plus updates for VMware Cloud Foundation. But the company cautioned that the workaround is just a stop-gap—it won’t fix the two additional vulnerabilities revealed with CVE-2026-22719.

The vulnerability stems from a “support-assisted” migration workflow—a particular state triggered in some customer environments during vendor-supported migrations. That detail might limit how many systems are actually exposed. Still, with CISA flagging it as exploited, defenders are likely to start treating the risk with more urgency.

Customers now face yet another round of patching, this time across intricate stacks—think virtualization, monitoring, and cloud management software from players like Microsoft and IBM’s Red Hat—plus whatever security and hardware layers are already in place.

Broadcom’s quarterly numbers drop after Wednesday’s close, and options traders are braced for a swing—roughly 8% up or down—depending on how results shake out. Visible Alpha’s projections land at $19.21 billion in fiscal Q1 revenue with adjusted EPS pegged at $2.02, according to Investopedia.

Broadcom is pushing its VMware-based private cloud to telecom operators looking to set up “sovereign” infrastructure—systems meant to keep critical data and operations within national borders. “Hardware costs are spiraling out of control and the global demand for memory resulting from AI will further accelerate rising server prices,” said Paul Turner, chief product officer for Broadcom’s VMware Cloud Foundation group, in a statement quoted by Channel Dive. Channel Dive

Broadcom’s $69 billion acquisition of cloud software player VMware in 2023 brought infrastructure software deeper into the mix, complementing its core chip business.

The risk on the table is clear enough: should attackers exploit the flaw on a wider scale, big companies and service providers that can’t just schedule downtime could find themselves rushing to patch. Broadcom, for its part, says it can’t verify the exploit reports, which doesn’t help. Defenders are now being pushed to act quickly, without much in the way of public specifics on the attack methods.

Stock Market Today

  • Watsco (WSO) Declares Quarterly Dividend Ahead of Ex-Dividend Date
    April 14, 2026, 10:48 AM EDT. Watsco Inc. (WSO) will trade ex-dividend on October 16, 2024, for its quarterly dividend of $2.70 per share. This payout represents about 0.55% of WSO's recent share price near $491.58. The dividend will be payable on October 31, 2024. Shares typically drop by the dividend yield on the ex-date, so WSO shares may open lower by approximately 0.55% following the ex-dividend date. The stock has traded between $338.58 and $520.41 over the past year, and the current annualized dividend yield stands near 2.20%. WSO shares recently gained about 1.5% during Monday trading, reflecting sustained investor interest ahead of the dividend.

Latest article

Meta Builds AI Version of Mark Zuckerberg for Employees as AI Push Leaves Metaverse Behind

Meta Builds AI Version of Mark Zuckerberg for Employees as AI Push Leaves Metaverse Behind

14 April 2026
Meta is developing an AI version of CEO Mark Zuckerberg, trained on his image, voice, and public statements to interact with employees, the Financial Times reported. The company ended 2025 with 78,865 staff and expects 2026 capital spending of $115–$135 billion, mostly for AI infrastructure and talent. Reuters said Meta has shifted top engineers into a new Applied AI group as part of its internal AI push.
Johnson & Johnson Earnings Beat Estimates, J&J Raises 2026 Outlook Despite Stelara Slump

Johnson & Johnson Earnings Beat Estimates, J&J Raises 2026 Outlook Despite Stelara Slump

14 April 2026
Johnson & Johnson reported first-quarter revenue of $24.1 billion, up 9.9%, and adjusted earnings of $2.70 per share, both above analyst estimates. Sales of cancer drug Darzalex hit $4 billion, while Stelara fell 60% to $656 million. The company raised its 2026 outlook, nudging full-year sales guidance to $100.8 billion. J&J shares slipped 0.27% to $237.96 in early trading.
Wells Fargo Profit Beats in Q1, But Revenue Miss and Lower Rates Hit Shares

Wells Fargo Profit Beats in Q1, But Revenue Miss and Lower Rates Hit Shares

14 April 2026
Wells Fargo reported a 7% rise in first-quarter net income to $5.25 billion, beating profit estimates, but missed on revenue and core lending metrics, sending shares lower premarket. Net interest income came in at $12.1 billion, short of forecasts, while noninterest income also missed expectations. Provision for credit losses rose 22% to $1.135 billion. The bank kept its 2026 outlook unchanged.
IREN stock jumps as AI data-center race heats up after CoreWeave, Nebius deals

IREN stock jumps as AI data-center race heats up after CoreWeave, Nebius deals

14 April 2026
IREN shares rose to $43.07 Tuesday, up $3.76, as Meta’s $21 billion CoreWeave deal and Nebius’ up-to-$27 billion Meta agreement fueled interest in AI infrastructure stocks. IREN aims for a 150,000-GPU buildout and targets over $3.7 billion in annualized AI cloud revenue by end-2026, though most is not yet contracted. Microsoft’s $9.7 billion contract and $3.6 billion in GPU financing back the expansion.
T-Mobile sues Verizon back over “Better Deal” ads as false-ad fight escalates
Previous Story

T-Mobile sues Verizon back over “Better Deal” ads as false-ad fight escalates

Why Alphabet’s Google Class C stock (GOOG) is in focus today: Trump’s power pledge and a new Waymo probe
Next Story

Why Alphabet’s Google Class C stock (GOOG) is in focus today: Trump’s power pledge and a new Waymo probe

Go toTop