VMware Aria Operations
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*
- >= 8, <= 8.18.5
- >= 9, <= 9.0.1
This vulnerability is being actively exploited in the wild.
A command injection vulnerability has been identified in VMware Aria Operations. This vulnerability allows a malicious, unauthenticated actor to execute arbitrary commands, potentially leading to remote code execution, while support-assisted product migration is in progress. The issue is present in VMware Aria Operations versions 8.18.x prior to 8.18.6 and 9.0.x prior to 9.0.1.
Exploitation of this vulnerability could result in unauthorized command execution, with the possibility of remote code execution on the affected system.
To address this vulnerability, users can upgrade to VMware Aria Operations versions 8.18.6 or 9.0.2. For those using VMware Cloud Foundation, version 5.2.3 is available. Workaround instructions are also available for CVE-2026-22719.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.