CVE-2026-22719
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.
CISA KEV
- Vendor
- Broadcom
- Product
- VMware Aria Operations
- Due date
- 2026-03-24
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.