This article provides the prerequisites and general steps to upgrade VMware Aria Operations environments from 8.18.x to 8.18.6 to address the vulnerabilities detailed in VMSA-2026-0001.
These security updates mitigate an unauthenticated remote code execution risk (CVE-2026-22719) that can occur during product migrations.
VMware Aria Operations 8.18.x
IMPORTANT Pre-Requisites:
.pak extraction and upgrade process./data directory). In the ASLCM UI, navigate to Lifecycle Operations > Settings > Binary Mapping. Set the Source Location, click Discover, and then Add.https://<master-node-IP>/admin. Click Take Cluster Offline, provide a reason when prompted, and wait for the cluster status to change to offline..pak file, accept the EULA, and start the installation.If the upgrade process fails, please gather the support bundle for Aria Operations from when the patch failed and reach out to Broadcom Support.