Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 24, 2026

CVE-2026-22719

High
EPSS 7.4%CISA KEV
Broadcom/VMware Aria Operations

Description

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.

EPSS — Exploit Probability

7.4%

Higher than 91.6% of all CVEs

Required Action

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ; https://knowledge.broadcom.com/external/article/430349 ; https://nvd.nist.gov/vuln/detail/CVE-2026-22719

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
7.4%
CISA KEV
Yes
Ransomware
Unknown
Articles
3

Timeline

Published

Mar 3, 2026

Added to KEV

Mar 3, 2026

Remediation Due

Mar 24, 2026

Affected Product

Broadcom

VMware Aria Operations

View all Broadcom CVEs