CVE-2026-22719
published 2026-02-25CVE-2026-22719: VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which…
PriorityP186high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-03-24
Exploited in the wild
EPSS
17.42%
96.8th percentile
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.
To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | aria_operations | >= 8.0 < 8.18.6 | 8.18.6 |
| vmware | cloud_foundation | >= 4.0 < 5.2.3 | 5.2.3 |
| vmware | cloud_foundation | >= 9.0 < 9.0.2.0 | 9.0.2.0 |
| vmware | telco_cloud_infrastructure | >= 2.0 < 5.2.3 | 5.2.3 |
| vmware | telco_cloud_infrastructure | 2.2 – 3.0 | — |
| vmware | telco_cloud_platform | >= 2.0 < 5.2.3 | 5.2.3 |
| vmware | telco_cloud_platform | 4.0 – 5.1 | — |
| vmware | vmware_aria_operations | >= 8.18.x < 8.18.6 | 8.18.6 |
| vmware | vmware_cloud_foundation_operations | >= 4.0 < 5.2.3 | 5.2.3 |
| vmware | vmware_cloud_foundation_operations | >= 9.0 < 9.0.2 | 9.0.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated command injection attempts targeting VMware Aria Operations during support-assisted product migration workflows; exploitation occurs while migration is in progress. ↗
- →Alert on execution of vmware-casa-migration-service.sh or vmware-casa-workflow.sh from unexpected or unauthenticated contexts, especially invocations running as root via sudoers NOPASSWD. ↗
- →Affected versions are Aria Operations 8 through 8.18.5 and 9 through 9.0.1; prioritize detection and patching on these version ranges. ↗
- →Check sudoers configuration on Aria Operations nodes for the NOPASSWD entry permitting vmware-casa-workflow.sh to run as root, which is the abusable privilege escalation path. ↗
- ·Exploitation is only possible while support-assisted product migration is actively in progress; attack surface is conditional on this operational state. ↗
- ·The workaround script must be executed as root on EACH Aria Operations appliance node individually; partial deployment leaves nodes exposed. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck8.1HIGH
cisa8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Broadcom VMware Aria Operations Command Injection Vulnerability
cisa·2026-03-03·CVSS 8.1
CVE-2026-22719 [HIGH] CWE-77 Broadcom VMware Aria Operations Command Injection Vulnerability
Vulnerability: Broadcom VMware Aria Operations Command Injection Vulnerability
Affected: Broadcom VMware Aria Operations
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CV
GHSA
GHSA-2hp7-6cr6-jvxh: VMware Aria Operations contains a command injection vulnerability
ghsa_unreviewed·2026-02-25·CVSS 8.1
CVE-2026-22719 [HIGH] CWE-77 GHSA-2hp7-6cr6-jvxh: VMware Aria Operations contains a command injection vulnerability
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.
To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
VulnCheck
Broadcom VMware Aria Operations Command Injection Vulnerability
vulncheck·2026·CVSS 8.1
CVE-2026-22719 [HIGH] CWE-77 Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
Affected: Broadcom VMware Aria Operations
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Reme
No detection rules found.
No public exploits indexed.
Checkpoint
9th March – Threat Intelligence Report
blogs_checkpoint·2026-03-09
CVE-2026-0628 9th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th March, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
AkzoNobel, a Netherlands-based global paint manufacturer, has confirmed a cyberattack affecting one of its United States sites. The company said the intrusion was contained, while the Anubis ransomware group claimed it stole 170 GB of data, including employee and financial records.
LexisNexis, a global legal data and analytics
Bleepingcomputer
CISA flags VMware Aria Operations RCE flaw as exploited in attacks
blogs_bleepingcomputer·2026-03-03·CVSS 8.1
CVE-2026-22719 [HIGH] CISA flags VMware Aria Operations RCE flaw as exploited in attacks
## CISA flags VMware Aria Operations RCE flaw as exploited in attacks
## Lawrence Abrams
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the flaw as exploited in attacks.
Broadcom also warned that it is aware of reports indicating the vulnerability is exploited but says it cannot independently confirm the claims.
VMware Aria Operations is an enterprise monitoring platform that helps organizations track the performance and health of servers, networks, and cloud infrastructure.
The vulnerability was originally disclosed and patched on February 24, 2026, as part of VMware's VMSA-2026-0001 advisory, which was rated Important with a CVSS score
https://knowledge.broadcom.com/external/article/430349https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-operations/8-18/vmware-aria-operations-8186-release-notes.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22719
2026-02-25
Published
2026-03-03
Added to CISA KEV
Exploited in the wild