CVE Tools

CVE-2026-22719

VMware Aria Operations command injection vulnerability

Published: Feb 25, 2026Updated: Mar 4, 2026 Sources: CVE List NVD BDUCWE-77

Description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

In plain language

AI Act now

CVE-2026-22719 is a VMware Aria Operations flaw that can let an attacker run commands on your server without logging in, but it only works during a support-assisted migration process—still, because it’s in the CISA Known Exploited list, affected small businesses should act now and upgrade to the fixed versions.

Executive summary

CVE-2026-22719 is a command injection in VMware Aria Operations that allows unauthenticated remote attackers to execute arbitrary system commands as a high-privileged user during support-assisted product migration, and it is listed in CISA KEV (required mitigation by 2026-03-24).

If affected, business impact
Full server takeoverRansomware-style damageLoss of control of monitoringPotential data theft

What to do now

  1. Check whether your organization runs VMware Aria Operations (including VMware Cloud Foundation/Telco Cloud variants that use Aria Operations) and whether you are in or about to start a support-assisted product migration window.
  2. Confirm your current version and compare it to the vendor-fixed versions: VMware Aria Operations 8.18.6 and VMware Cloud Foundation Operations (and Telco Cloud Platform/Infrastructure) 9.0.2 or 5.2.3 depending on your branch.
  3. Upgrade immediately to the fixed versions: VMware Aria Operations 8.18.6; VMware Cloud Foundation Operations 9.0.2 (or 5.2.3 for the applicable branch); Telco Cloud Platform 5.2.3; Telco Cloud Infrastructure 5.2.3.
  4. If you cannot patch right away, apply the vendor-documented workaround from VMSA-2026-0001 (KB430349) and reduce exposure as far as your operations allow.
  5. After patching, verify the migration/task is completed and keep the system under closer monitoring for unusual process execution and unexpected admin-level activity.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 3, 2026
Remediation due:Mar 24, 2026

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available
Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 7 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-22719 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store