CISA added CVE-2024-37079, a critical VMware vCenter Server vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog after Broadcom indicated it has evidence of in-the-wild exploitation. The flaw is a 9.8 CVSS out-of-bounds write/heap-overflow issue in vCenter Server’s DCERPC implementation; an attacker with network access can send specially crafted packets that may result in remote code execution (RCE). CISA’s KEV entry does not attribute exploitation to a specific threat actor and lists ransomware use as unknown, but the KEV addition triggers mandatory remediation timelines for US federal agencies.
Reporting also noted CISA added multiple other enterprise software issues to KEV in a short span (including vulnerabilities affecting Versa Concerto and Zimbra, plus developer tools), but the vCenter Server item drew specific attention because it was patched by Broadcom in 2024 and is still being exploited. Broadcom has not publicly provided details on the scope, victims, or exploitation chain beyond acknowledging observed exploitation, reinforcing the need for organizations running vCenter Server to validate exposure and ensure the relevant updates are deployed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-23, CISA added CVE-2024-37079 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The agency required U.S. federal civilian agencies to remediate the flaw by 2026-02-13.
On 2026-01-23, Broadcom updated its advisory to state it had information indicating in-the-wild exploitation of VMware vCenter Server flaw CVE-2024-37079. The company did not disclose threat actors, campaign scope, or technical details of the attacks.
Across 2026-01-22 and 2026-01-23, CISA also added CVE-2025-34026 (Versa Concerto), CVE-2025-68645 (Zimbra), CVE-2025-31125 (Vite), and CVE-2025-54313 (eslint-config-prettier supply-chain compromise) to the KEV catalog. Federal remediation deadlines were set for 2026-02-12 for these four vulnerabilities.
On 2024-06-18, Broadcom/VMware released security advisory VMSA-2024-0012 with fixes for CVE-2024-37079 and related vCenter Server vulnerabilities, including another critical DCERPC heap overflow. The flaws could be triggered via crafted network packets and exposed unpatched vCenter deployments to possible remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethecyberthrone.in
Open sourcethecyberexpress.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.