Broadcom’s VMware Aria bug hits CISA exploited list, setting patch clock for agencies
CISA added Broadcom’s VMware Aria Operations vulnerability CVE-2026-22719 to its exploited-bugs list, ordering federal agencies to patch by March 24. Broadcom acknowledged reports of possible exploitation but said it could not confirm them. Patches and a workaround are available. The alert comes as Broadcom prepares to report quarterly earnings after the market close.