PT-2026-21684 · Vmware · Vmware Aria Operations

Published

2026-02-24

·

Updated

2026-04-02

·

CVE-2026-22719

CVSS v3.1

8.1

High

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: VMware Aria Operations versions 8.0 through 8.18.5 and 9.0 through 9.0.1.
Description: VMware Aria Operations contains a command injection vulnerability that allows a malicious unauthenticated actor to execute arbitrary commands, potentially leading to remote code execution during support-assisted product migration. This vulnerability is actively exploited in the wild and has been added to CISA's KEV catalog.
Recommendations: Upgrade VMware Aria Operations to version 8.18.6 or later, or VMware Cloud Foundation to version 9.0.2.0 or later. If immediate patching is not possible, apply the workaround script provided by Broadcom.

Fix

RCE

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-02323
CVE-2026-22719

Affected Products

Vmware Aria Operations