cve detail

CVE-2026-22719

naam
Broadcom VMware Aria Operations Command Injection Vulnerability

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.

KEV
bekend misbruikt
EPSS
2,1%
percentiel
84%
vendor
Broadcom
product
VMware Aria Operations
toegevoegd aan KEV
03 mrt 2026
due date
24 mrt 2026
ransomware
Unknown
CWE
CWE-77
EPSS datum
12 mei 2026
aanbevolen actie

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

notities

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719