← Back to CVE List
Vulnerability Intelligence Report
VMware Aria Operations command injection vulnerability

CVE-2026-22719

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.1
HIGH
Exploitability:2.3
Impact Score:5.9
EPSS Probability:17.42%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-77 ↗CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
VMware VMware Aria Operations 8.18.x < 8.18.6 (affected)
VMware VMware Cloud Foundation Operations 9.0 < 9.0.2 (affected), 9.0.2 (unaffected), 4.0 < 5.2.3 (affected), 5.2.3 (unaffected)
VMware Telco Cloud Platform 2.0 < 5.2.3 (affected), 5.2.3 (unaffected)
VMware Telco Cloud Infrastructure 2.0 < 5.2.3 (affected), 5.2.3 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
17.424%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVMware by Broadcom · Vendor · USA
Reserved2026-01-09T06:54:36
Published2026-02-25T19:18:59
Patch Date2026-02-24
Last Updated2026-04-14T10:38:25

LINK COPIED TO CLIPBOARD