A vulnerability was recently announced regarding the NGINX ngx_http_rewrite_module, tracked under CVE-2026-42945.
The purpose of this article is to provide information and confirmation regarding the impact of this specific vulnerability on the VMware Aria Automation Orchestrator product.
VMware Aria Automation 8.18.x
VMware Aria Automation Orchestrator 8.18.x
VMware By Broadcom is aware of CVE-2026-42945.
Refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information or support, contact Broadcom Support.