🔴 CVE-2026-22719

Command injection vulnerability in VMware Aria Operations allows unauthenticated remote code execution during support-assisted product migration. Affects critical enterprise infrastructure management platforms commonly exposed to internet.

← Back to Overview
HIGH_RISK
Risk Level
8.1
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-02-25

Added to CISA KEV: 2026-03-03 6 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-03-03)

CVE-2026-22719 is a command injection vulnerability affecting VMware Aria Operations [2][8].

Here's a breakdown of what is known about its exploitation:

  • Internet-Facing Applications or Services: The vulnerability is present in VMware Aria Operations, which can be internet-facing, especially when support-assisted product migration is in progress [1][2].
  • Evidence of Active Exploitation: There is currently no indication of active exploitation in the wild [4].
  • Attack Vectors and Exploitation Methods:
* A malicious unauthenticated actor can exploit this vulnerability [1][2]. * Exploitation is possible while support-assisted product migration is in progress [1][2]. * The vulnerability allows for the execution of arbitrary commands, which can lead to remote code execution (RCE) [1][2]. * The CVSS score for this vulnerability is 8.1 (High) [9][10]. * While the exploitability is considered high due to the lack of privilege requirements, the attack complexity is also noted as high, meaning specific conditions must be met for a successful exploit [1][5].
  • Targeted Attacks: There is no specific information available regarding whether this vulnerability has been used in targeted attacks.
  • CISA Known Exploited Vulnerabilities (KEV) Status: CVE-2026-22719 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) Catalog [3][11].
  • Technical Details about Internet Exploitability: The vulnerability allows an unauthenticated actor to execute arbitrary commands remotely, specifically during the support-assisted product migration process [1][2]. This implies that the exploitability is tied to the availability and execution of this specific migration process.
To remediate CVE-2026-22719, it is recommended to apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in VMware Security Advisory VMSA-2026-0001 [2][6]. Workarounds are also documented in the 'Workarounds' column of the same matrix [7].

Sources

  1. CVE-2026-22719 Security Vulnerability & Exploit Details

    CVE-2026-22719 presents a challenge to exploit due to its high attack complexity, but the absence of privilege requirements still makes it a viable target for skilled attackers. A thorough security review is advised.Below is the Impact Analysis for CVE-2026-22719, showing how Confidentiality, Integr…

  2. CVE-2026-22719 Detail - NVD

    Information Technology Laboratory. National Vulnerability Database.A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-2…

  3. Known Exploited Vulnerabilities Catalog - CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catal…

  4. VMware cloud management platform in triple threat -

    The new advisory revealed VMware Aria Operations is at risk from a triple threat of a command injection vulnerability (CVE-2026-22719), a stored cross-site scripting vulnerability (CVE-2026-22720), and a privilege escalation vulnerability (CVE-2026-22721). ... is currently no indication of active ex…

  5. CVE-2026-27119 Security Vulnerability & Exploit Details

    CVE-2026-27119 - svelte performance oriented web framework. From 5.39.3, <=5.51.4, in certain circumstances, the server-side rendering output of…Above is the CVSS Sub-score Breakdown for CVE-2026-27119, illustrating how Base, Impact, and Exploitability factors combine to form the overall severity ra…