CVE-2026-22719
VMware Aria Operations command injection vulnerability
Description
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
In plain language
AI Act nowCVE-2026-22719 is a VMware Aria Operations flaw that can let an attacker run commands on your server without logging in, but it only works during a support-assisted migration process—still, because it’s in the CISA Known Exploited list, affected small businesses should act now and upgrade to the fixed versions.
CVE-2026-22719 is a command injection in VMware Aria Operations that allows unauthenticated remote attackers to execute arbitrary system commands as a high-privileged user during support-assisted product migration, and it is listed in CISA KEV (required mitigation by 2026-03-24).
What to do now
- Check whether your organization runs VMware Aria Operations (including VMware Cloud Foundation/Telco Cloud variants that use Aria Operations) and whether you are in or about to start a support-assisted product migration window.
- Confirm your current version and compare it to the vendor-fixed versions: VMware Aria Operations 8.18.6 and VMware Cloud Foundation Operations (and Telco Cloud Platform/Infrastructure) 9.0.2 or 5.2.3 depending on your branch.
- Upgrade immediately to the fixed versions: VMware Aria Operations 8.18.6; VMware Cloud Foundation Operations 9.0.2 (or 5.2.3 for the applicable branch); Telco Cloud Platform 5.2.3; Telco Cloud Infrastructure 5.2.3.
- If you cannot patch right away, apply the vendor-documented workaround from VMSA-2026-0001 (KB430349) and reduce exposure as far as your operations allow.
- After patching, verify the migration/task is completed and keep the system under closer monitoring for unusual process execution and unexpected admin-level activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-22719 and every CVE in our database. Create a free account — no credit card required.
Create Free Account