logo

CVE-2026-22719: VMware Aria Operations Command Injection Added to CISA KEV

ID: 1908d438-a918-59d0-9c73-18f4fbcf151c

STIX ID: report--1908d438-a918-59d0-9c73-18f4fbcf151c

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-03-04

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**CVE-2026-22719 — VMware Aria Operations command injection:** CISA added this unauthenticated RCE vulnerability to its Known Exploited Vulnerabilities catalog; affected Aria Operations versions include 8.x ≤ 8.18.5 and 9.x ≤ 9.0.1, Broadcom has released fixes (8.18.6, 9.0.2) and provides a workaround script (aria-ops-rce-workaround.sh); organizations should prioritize patching or apply the workaround and restrict management access, especially during support-assisted migrations, with CISA’s remediation deadline of March 24, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.