Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability concerning VMware's vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, identified as CVE-2024-37079 , poses a significant…

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability concerning VMware's vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, identified as CVE-2024-37079 , poses a significant risk due to confirmed active exploitation.

The vulnerability is categorized as an out-of-bounds write issue linked to the DCERPC (Distributed Computing Environment / Remote Procedure Calls) protocol. Exploitation allows unauthorized network access to execute remote code on the vCenter Server, potentially compromising the entire system.

This flaw arises from improper memory management within the DCERPC protocol implementation. An attacker can exploit it by dispatching specifically crafted network packets to the vCenter Server. Given vCenter's role as a central management tool for VMware vSphere environments, a breach could enable lateral movement across virtualized infrastructures.

The vulnerability is associated with CWE-787 ( Out-of-bounds Write ) and is particularly concerning as it requires no user interaction and is network-based.

This vulnerability, identified as CVE-2024-37079 , poses a significant risk due to confirmed active exploitation.
Katherine Doyle · Thehackingpost

CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies address this vulnerability by February 13, 2026, following its inclusion in the KEV catalog on January 23, 2026. Organizations are urged to prioritize patching, applying vendor-provided mitigations, or discontinuing use if necessary.

Broadcom has released updates to mitigate this issue. Administrators are advised to upgrade to the latest secure versions.

To protect against this threat, recommended actions include:

Advertisement

Patch Immediately: Apply patches as outlined in Broadcom's security advisory. Network Segmentation: Restrict vCenter Server interfaces from public internet exposure and limit access to trusted networks. Monitor Traffic: Implement monitoring for unusual DCERPC traffic targeting vCenter servers. Review Logs: Audit access logs for unauthorized connection attempts to the management interface.

Organizations have a limited timeframe to address this critical vulnerability before it becomes a common target for automated exploitation tools.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories