cve detail
CVE-2026-22719
naam
Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
KEV
bekend misbruikt
EPSS
2,1%
percentiel
84%
vendor
Broadcom
product
VMware Aria Operations
toegevoegd aan KEV
03 mrt 2026
due date
24 mrt 2026
ransomware
Unknown
CWE
CWE-77
EPSS datum
12 mei 2026
aanbevolen actie
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
notities
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719