Answer in brief
CVE-2026-22719 records a High severity vulnerability in VMware Aria Operations command injection vulnerability. The current sources mark it as known exploited. The current feed maps VMware/Telco Cloud Infrastructure (generic), VMware/Telco Cloud Platform (generic), VMware/VMware Aria Operations (generic), VMware/VMware Cloud Foundation Operations (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps VMware/Telco Cloud Infrastructure (generic), VMware/Telco Cloud Platform (generic), VMware/VMware Aria Operations (generic), VMware/VMware Cloud Foundation Operations (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| VMware/Telco Cloud Infrastructuregeneric | >=2.0 <5.2.3 | 5.2.3 |
| VMware/Telco Cloud Platformgeneric | >=2.0 <5.2.3 | 5.2.3 |
| VMware/VMware Aria Operationsgeneric | >=8.18.x <8.18.6 | 8.18.6 |
| VMware/VMware Cloud Foundation Operationsgeneric | >=9.0 <9.0.2 || >=4.0 <5.2.3 | 9.0.2, 5.2.3 |
Published upstream
Feb 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Apr 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Mar 3, 2026
Evidence: source:kev:kev:kev:recordVMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-22719 records a High severity vulnerability in VMware Aria Operations command injection vulnerability. The current sources mark it as known exploited. The current feed maps VMware/Telco Cloud Infrastructure (generic), VMware/Telco Cloud Platform (generic), VMware/VMware Aria Operations (generic), VMware/VMware Cloud Foundation Operations (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps VMware/Telco Cloud Infrastructure (generic), VMware/Telco Cloud Platform (generic), VMware/VMware Aria Operations (generic), VMware/VMware Cloud Foundation Operations (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| VMware/Telco Cloud Infrastructuregeneric | >=2.0 <5.2.3 | 5.2.3 |
| VMware/Telco Cloud Platformgeneric | >=2.0 <5.2.3 | 5.2.3 |
| VMware/VMware Aria Operationsgeneric | >=8.18.x <8.18.6 | 8.18.6 |
| VMware/VMware Cloud Foundation Operationsgeneric | >=9.0 <9.0.2 || >=4.0 <5.2.3 | 9.0.2, 5.2.3 |
Published upstream
Feb 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Apr 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Mar 3, 2026
Evidence: source:kev:kev:kev:recordVMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001 Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001
Quoted source text, attributed separately from HOL analysis.