logo

U.S. CISA adds Qualcomm and Broadcom VMware Aria Operations flaws to its Known Exploited Vulnerabilities catalog

ID: 28854840-236d-5f2b-b7d4-6a66edb68eab

STIX ID: report--28854840-236d-5f2b-b7d4-6a66edb68eab

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added two high-severity flaws to its Known Exploited Vulnerabilities catalog: CVE-2026-22719, a Broadcom/VMware Aria Operations command injection that can lead to remote code execution, and CVE-2026-21385, a Qualcomm graphics component memory corruption affecting Android devices that Google reports may be under limited targeted exploitation; CISA ordered federal agencies to remediate by March 24, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.