peter bassill · operator
$ cve CVE-2026-22719 JSON

CVE-2026-22719 KEV

8.1
HIGH · CVSS 3.1 · EPSS 17.7% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2026-03-24.

Description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.71% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2026-03-24
Public exploitnone known
Published2026-02-25
Last modified2026-06-17

CISA KEV

NameBroadcom VMware Aria Operations Command Injection Vulnerability
Added2026-03-03
Due2026-03-24
Vendor / productBroadcom / VMware Aria Operations
Ransomware usenone reported

Affected (4)

VendorProduct
vmwarearia operations
vmwarecloud foundation
vmwaretelco cloud infrastructure
vmwaretelco cloud platform

References

→ the Explorer  ·  watch your stack  ·  NVD