Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2026-03-03 — agencies required to remediate by 2026-03-24

CVE-2026-22719

HIGH

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code…

Published
Feb 25, 2026
Updated
Mar 4, 2026
Affected
0 pkgs
Patched
None yet
Exploits
None indexed

EPSS Exploitation Probability

via FIRST.org ↗
1.9%probability of exploitation in next 30 days
Lower Risk84th percentile-0.19%
0.00%0.87%1.75%2.62%0.3%2.1%2.0%2.1%1.9%Mar 26May 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Description

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. 

To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 

Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

Affected Products

4 products · 5 configurations
Application
aria operationsvmware
≥ 8.0 && < 8.18.6
range
Application
cloud foundationvmware
≥ 9.0 && < 9.0.2.0
range
Application
telco cloud infrastructurevmware
≥ 2.2 && ≤ 3.0
range
Application
telco cloud platformvmware
≥ 4.0 && ≤ 5.1
range

Frequently Asked Questions

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of t
O3 Security · Impact-Aware SCA

Is CVE-2026-22719 in your stack?

O3 detects CVE-2026-22719 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.