logo

Patch or die: VMware vCenter Server bug fixed in 2024 under attack today

ID: 4b2997ad-1afb-5e1e-b850-b7a682234237

STIX ID: report--4b2997ad-1afb-5e1e-b850-b7a682234237

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-01-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical out-of-bounds write vulnerability in VMware vCenter Server's DCERPC implementation (CVE-2024-37079, CVSS 9.8) can enable remote code execution; Broadcom indicates exploitation in the wild and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Broadcom issued a patch in June 2024; organizations are urged to patch affected vCenter Servers and avoid exposing them to the public internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.