A recently patched vulnerability in VMware Aria Operations (formerly vRealize Operations) has been exploited in the wild, the cybersecurity agency CISA warned on Tuesday.
The vulnerability, tracked as CVE-2026-22719, is a high-severity command injection issue that can be exploited without authentication.
“A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress,” Broadcom explained in a February 24 advisory announcing patches for the flaw.
CISA added CVE-2026-22719 to its Known Exploited Vulnerabilities (KEV) catalog on Tuesday, instructing federal agencies to address it by March 24.
There appears to be no public information describing attacks involving the vulnerability.
In an update to its initial advisory, Broadcom noted, “Broadcom is aware of reports of potential exploitation of CVE-2026-22719 in the…