FOFA[verified]@fofabotActive Exploitation
CVE‑2026‑22719 is an actively exploited command injection flaw in VMware Aria Operations (CVSS 8.1) that allows unauthenticated remote code execution during migration, with evidence from FOFA and external reports but no patch or PoC provided.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
CISA has identified CVE-2026-22719 as an actively exploited vulnerability in VMware Aria Operations and added it to the KEV catalog.
Blue Team News[verified]@blueteamsec1Active Exploitation
CISA reports that VMware Aria Operations CVE-2026-22719 is being actively exploited and adds it to the KEV catalog.
piyokango[verified]@piyokangoActive Exploitation
CISA confirmed active exploitation of two CVEs, providing detailed technical information and vendor advisory links, but no PoC or exploit code was disclosed.
Modat[verified]@modat_magnifyActive Exploitation
CISA identifies CVE-2026-22719 as an actively exploited unauthenticated command injection flaw in VMware Aria Operations and related products, urging immediate patching or vendor workarounds to prevent remote code execution.
Cyber News Live[verified]@cybernewsliveActive Exploitation
VMware Aria Operations is experiencing active exploitation via a command injection flaw (CVE-2026-22719); users are urged to patch to 8.18.6/9.0.2.0 or apply Broadcom’s workaround script.
ctrlaltnod[verified]@ctrlaltnodActive Exploitation
The article reports that CVE-2026-22719 in VMware Aria Operations is being exploited in the wild with RCE, prompting CISA to urge urgent patching.
Nicolas Krassas[verified]@DinosnActive Exploitation
CISA has identified CVE-2026-22719 as an actively exploited vulnerability in VMware Aria Operations and added it to the KEV catalog.