CVE-2026-22719 is a critical command injection vulnerability affecting VMware Aria Operations, Cloud Foundation, and Telco Cloud products. This flaw allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support-assisted product migration. Rated 8.1 High on CVSS, the vulnerability has a network attack vector with high complexity, requiring no privileges or user interaction, and resulting in high impact to confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and active media coverage, despite no public exploit code being available on common platforms. Organizations are urged to apply patches or workarounds immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.18.6CPE matchmatch criteria | cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:* | ||
>= 4.0, < 5.2.3CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.0.2.0CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
>= 2.2, <= 3.0CPE matchmatch criteria | cpe:2.3:a:vmware:telco_cloud_infrastructure:*:*:*:*:*:*:*:* | ||
>= 4.0, <= 5.1CPE matchmatch criteria | cpe:2.3:a:vmware:telco_cloud_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.