Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 17.4%; technical severity is CVSS 8.1.
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Who should care
- Teams operating VMware Aria Operations, Aria Operations, Cloud Foundation +2 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether VMware Aria Operations, Aria Operations, Cloud Foundation +2 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Broadcom Security patch
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-77
- Affected versions
- Broadcom VMware Aria Operations; VMware Aria Operations (Start Including 8.0, End Excluding 8.18.6); VMware Cloud Foundation (Start Including 4.0, End Excluding 5.2.3 | Start Including 9.0, End Excluding 9.0.2.0); VMware Telco Cloud Infrastructure (Start Including 2.2, End Including 3.0); VMware Telco Cloud Platform (Start Including 4.0, End Including 5.1)
- Fixed versions
- VMware Aria Operations (Fixed from 8.18.6); VMware Cloud Foundation (Fixed from 5.2.3, 9.0.2.0)
- Published
- 25 February 2026
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 17.4%
- Signal calculated at 71