EXPOSURES › CVE-2026-22719
CVE-2026-22719
HIGH ⌖ ON CISA KEV · EXPLOITEDBroadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations.
An unpatched command injection vulnerability in Broadcom's VMware Aria Operations allowed unauthenticated attackers to execute arbitrary commands, potentially leading to remote code execution during support-assisted product migrations. This highlights the importance of prompt patching and rigorous security reviews for DIB systems.
Shame score — An actively exploited unpatched vulnerability in a DIB-critical system.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
| PRODUCT | STATUS |
|---|---|
| Clarity Broadcom |
Authorized |
| General Support Systems (GSS) Broadcom |
Authorized |
| Rally Broadcom |
Authorized |
| Symantec Gov Cloud Security (GCS) Broadcom |
In Process |