logo

CISA warns of VMware ESXi bug exploited in ransomware attacks

ID: 0cb1dbc8-14a7-5b43-87a6-ae5c9fab987b

STIX ID: report--0cb1dbc8-14a7-5b43-87a6-ae5c9fab987b

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-07-30

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

CISA ordered U.S. Federal Civilian Executive Branch agencies to secure ESXi servers against CVE-2024-37085, an authentication bypass in VMware ESXi that allows attackers to create an ESX Admins account and obtain full hypervisor privileges; the flaw (fixed in ESXi 8.0 U3) is being actively exploited by multiple ransomware groups to steal data, move laterally, and encrypt ESXi file systems, and CISA added it to its Known Exploited Vulnerabilities catalog with a three-week remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.