CISA updated its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation, adding CVE-2024-37079, an out-of-bounds write vulnerability affecting Broadcom VMware vCenter Server. CISA emphasized that KEV-listed issues represent frequent attack vectors and material risk to the federal enterprise, and reiterated that BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate KEV vulnerabilities by mandated due dates; CISA also urged non-federal organizations to prioritize KEV remediation as part of vulnerability management.
Separately, LevelBlue SpiderLabs highlighted renewed operational relevance of CVE-2009-0556, a legacy Microsoft PowerPoint memory-corruption/code-injection issue enabling arbitrary code execution via a crafted PowerPoint file (e.g., malformed OutlineTextRefAtom index). The post notes the vulnerability’s resurfacing after being added to the KEV Catalog (per the article, on 2026-01-07), using it as an example of how long-fixed flaws can re-emerge when legacy Office versions, backward-compatible components, or poor patch hygiene persist in enterprise environments.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2024-37079, an out-of-bounds write vulnerability affecting Broadcom VMware vCenter Server, to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.
CISA added CVE-2009-0556 to its Known Exploited Vulnerabilities Catalog, indicating evidence of active exploitation and renewed operational relevance for the long-known PowerPoint flaw.
In 2009, Ziv Mador and Cristian Craioveanu of the Microsoft Malware Team documented CVE-2009-0556, a memory-corruption/code-injection vulnerability in legacy Microsoft PowerPoint versions that could allow remote code execution via a crafted PowerPoint file.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.