← Back to browse · API

CVE-2026-22719

Severity
HIGH
CVSS
8.1
EPSS
0.17424
Risk score
63.5
CISA KEV
Yes
PoC
No
Published
2026-02-25
Modified
2026-04-14
First seen
2026-08-07
Aliases
EUVD-2026-8708, GHSA-2HP7-6CR6-JVXH
Products
Broadcom:VMware Aria Operations, VMware:Telco Cloud Infrastructure 2.0 <5.2.3, VMware:Telco Cloud Infrastructure patch: 5.2.3, VMware:Telco Cloud Platform 2.0 <5.2.3, VMware:Telco Cloud Platform patch: 5.2.3, VMware:VMware Aria Operations 8.18.x <8.18.6, VMware:VMware Cloud Foundation Operations 4.0 <5.2.3, VMware:VMware Cloud Foundation Operations 9.0 <9.0.2, VMware:VMware Cloud Foundation Operations patch: 5.2.3, VMware:VMware Cloud Foundation Operations patch: 9.0.2
Sources
cisa.gov CVE-2026-22719
euvd EUVD-2026-8708

Description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

References