logo

CISA Alert: Critical VMware vCenter RCE (CVSS 9.8) Now Exploited in the Wild

ID: 2d0645e3-5783-5a2b-a250-56cb6b27d3d7

STIX ID: report--2d0645e3-5783-5a2b-a250-56cb6b27d3d7

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-25

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA added CVE-2024-37079 — a critical (CVSS 9.8) out-of-bounds write/heap overflow in Broadcom VMware vCenter Server's DCERPC implementation — to its Known Exploited Vulnerabilities catalog after Broadcom confirmed in-the-wild exploitation; the flaw permits unauthenticated remote code execution via a single crafted network packet, and federal agencies are required to remediate by February 13, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.