logo

CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks

ID: 42024cd6-eefa-5392-bcca-2ebc98b55531

STIX ID: report--42024cd6-eefa-5392-bcca-2ebc98b55531

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-24

Date Updated: 2026-04-21

Author: Guru Baran

...
...

CISA has added CVE-2024-37079—a critical out-of-bounds write in VMware vCenter Server's DCERPC implementation that enables unauthenticated remote code execution—to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; Broadcom released patches and organizations are urged to patch immediately, restrict vCenter exposure, monitor DCERPC traffic, and audit logs to prevent broad compromise of virtual infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.