logo

Critical RCE bug in VMware vCenter Server now exploited in attacks

ID: 6c978e23-292a-5598-91e5-9748f07a4bf0

STIX ID: report--6c978e23-292a-5598-91e5-9748f07a4bf0

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Broadcom warns that attackers are exploiting two VMware vCenter vulnerabilities—CVE-2024-38812 (critical RCE via a heap overflow) and CVE-2024-38813 (privilege escalation to root)—affecting vCenter-containing products; VMware released and reissued patches after an initial fix proved incomplete, no workarounds are available, and impacted customers are strongly urged to apply the latest updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.