CISA updated its Known Exploited Vulnerabilities (KEV) Catalog to add two CVEs based on evidence of active exploitation: CVE-2026-21385 (Qualcomm Multiple Chipsets memory corruption) and CVE-2026-22719 (Broadcom VMware Aria Operations command injection). The KEV entry for CVE-2026-22719 notes the issue can allow an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support-assisted product migration; CVE-2026-21385 is described as a memory corruption flaw related to memory allocation alignment across multiple Qualcomm chipsets.
Under Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are required to remediate KEV-listed vulnerabilities by CISA’s specified due dates; the KEV catalog update reflects an increase in total entries (from 1529 to 1531) and sets a remediation due date of 2026-03-24 for CVE-2026-22719. CISA emphasized that while BOD 22-01 applies to FCEB agencies, all organizations should prioritize remediation of KEV-listed vulnerabilities as part of vulnerability management due to their frequent use as attack vectors.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Under Binding Operational Directive 22-01, CISA required Federal Civilian Executive Branch agencies to remediate CVE-2026-21385 and CVE-2026-22719 by 2026-03-24. CISA also urged all organizations to prioritize mitigation of the two actively exploited vulnerabilities.
On 2026-03-03, CISA added CVE-2026-21385 affecting multiple Qualcomm chipsets and CVE-2026-22719 affecting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The KEV catalog total increased from 1,529 to 1,531 entries.
Alongside its advisory, Broadcom made a temporary mitigation script available to disable vulnerable migration-related components for customers unable to patch immediately. Reporting also identified fixed releases including Aria Operations 8.18.6 and 9.0.2.
On 2026-02-24, Broadcom disclosed CVE-2026-22719 in VMware Aria Operations via advisory VMSA-2026-0001 and released patches. The command injection flaw can allow unauthenticated arbitrary command execution, potentially leading to remote code execution during support-assisted product migration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
9 references tracked. Mallory keeps watching after this page renders.
socradar.io
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcethecyberthrone.in
Open sourcedarkreading.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.