PT-2026-21684 · Vmware · Vmware Aria Operations

CVE-2026-22719

·

Published

2026-02-24

·

Updated

2026-05-08

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: VMware Aria Operations versions 8.0 through 8.18.5 and 9.0 through 9.0.1.
Description: VMware Aria Operations contains a command injection vulnerability that allows a malicious unauthenticated actor to execute arbitrary commands, potentially leading to remote code execution during support-assisted product migration. This vulnerability is actively exploited in the wild and has been added to CISA's KEV catalog.
Recommendations: Upgrade VMware Aria Operations to version 8.18.6 or later, or VMware Cloud Foundation to version 9.0.2.0 or later. If immediate patching is not possible, apply the workaround script provided by Broadcom.

Fix

RCE

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02323
CVE-2026-22719

Affected Products

Vmware Aria Operations