CVE-2026-22719
Broadcom VMware Aria Operations Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 17.42% probability · 97th percentile
- CISA KEV
- Listed 3 March 2026 · due 24 March 2026
- Weakness
- CWE-77
- Affected
- vmware/aria operations · vmware/cloud foundation · vmware/telco cloud infrastructure · vmware/telco cloud platform
- Source
- security@vmware.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719
References
- https://knowledge.broadcom.com/external/article/430349Mitigation, Vendor Advisory
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947Patch, Vendor Advisory
- https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.htmlRelease Notes
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.