CVE-2026-22719

Confirmed PUBLISHED

VMware Aria Operations command injection vulnerability

VMware · VMware Aria Operations, VMware Cloud Foundation Operations, Telco Cloud Platform, Telco Cloud Infrastructure

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.1 High EPSS 17.4%

At a Glance

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

cisa
CVE Published
Feb 25, 2026
Exploitation Reported
Jun 01, 2026
CVSS
8.1 High
EPSS
17.4%
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
VMware
VMware Aria Operations

VMware Aria Operations

8.18.x to < 8.18.6

Affected
VMware
VMware Cloud Foundation Operations

VMware Cloud Foundation Operations

9.0 to < 9.0.2

Affected
VMware
VMware Cloud Foundation Operations

VMware Cloud Foundation Operations

9.0.2

Unaffected
VMware
VMware Cloud Foundation Operations

VMware Cloud Foundation Operations

4.0 to < 5.2.3

Affected
VMware
VMware Cloud Foundation Operations

VMware Cloud Foundation Operations

5.2.3

Unaffected
VMware
Telco Cloud Platform

vmware-telco-cloud-platform

2.0 to < 5.2.3

Affected
VMware
Telco Cloud Platform

vmware-telco-cloud-platform

5.2.3

Unaffected
VMware
Telco Cloud Infrastructure

vmware-telco-cloud-infrastructure

2.0 to < 5.2.3

Affected
VMware
Telco Cloud Infrastructure

vmware-telco-cloud-infrastructure

5.2.3

Unaffected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.