Skip to content
COOEY

EXPOSURES › CVE-2026-22719

CVE-2026-22719

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-22719 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Broadcom's VMware Aria Operations had an unpatched command injection flaw exploited in the wild, allowing remote code execution during product migrations.

An unpatched command injection vulnerability in Broadcom's VMware Aria Operations allowed unauthenticated attackers to execute arbitrary commands, potentially leading to remote code execution during support-assisted product migrations. This highlights the importance of prompt patching and rigorous security reviews for DIB systems.

Shame score — An actively exploited unpatched vulnerability in a DIB-critical system.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Clarity
Broadcom
Authorized
General Support Systems (GSS)
Broadcom
Authorized
Rally
Broadcom
Authorized
Symantec Gov Cloud Security (GCS)
Broadcom
In Process