Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogwidely-deployed-product-advisory

CISA Flags Actively Exploited VMware vCenter Server RCE (CVE-2024-37079)

Updated 3mo agoFirst seen Jan 24, 20269 sources

CISA added CVE-2024-37079, a critical VMware vCenter Server vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog after Broadcom indicated it has evidence of in-the-wild exploitation. The flaw is a 9.8 CVSS out-of-bounds write/heap-overflow issue in vCenter Server’s DCERPC implementation; an attacker with network access can send specially crafted packets that may result in remote code execution (RCE). CISA’s KEV entry does not attribute exploitation to a specific threat actor and lists ransomware use as unknown, but the KEV addition triggers mandatory remediation timelines for US federal agencies.

Reporting also noted CISA added multiple other enterprise software issues to KEV in a short span (including vulnerabilities affecting Versa Concerto and Zimbra, plus developer tools), but the vCenter Server item drew specific attention because it was patched by Broadcom in 2024 and is still being exploited. Broadcom has not publicly provided details on the scope, victims, or exploitation chain beyond acknowledging observed exploitation, reinforcing the need for organizations running vCenter Server to validate exposure and ensure the relevant updates are deployed.

Share:
CISA Flags Actively Exploited VMware vCenter Server RCE (CVE-2024-37079)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 23, 20265mo ago

CISA adds VMware vCenter CVE-2024-37079 to the KEV catalog

On 2026-01-23, CISA added CVE-2024-37079 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The agency required U.S. federal civilian agencies to remediate the flaw by 2026-02-13.

Broadcom confirms CVE-2024-37079 has been exploited in the wild

On 2026-01-23, Broadcom updated its advisory to state it had information indicating in-the-wild exploitation of VMware vCenter Server flaw CVE-2024-37079. The company did not disclose threat actors, campaign scope, or technical details of the attacks.

Jan 22, 20265mo ago

CISA adds four more enterprise software flaws to KEV

Across 2026-01-22 and 2026-01-23, CISA also added CVE-2025-34026 (Versa Concerto), CVE-2025-68645 (Zimbra), CVE-2025-31125 (Vite), and CVE-2025-54313 (eslint-config-prettier supply-chain compromise) to the KEV catalog. Federal remediation deadlines were set for 2026-02-12 for these four vulnerabilities.

Jun 18, 20242y ago

Broadcom patches VMware vCenter DCERPC flaws

On 2024-06-18, Broadcom/VMware released security advisory VMSA-2024-0012 with fixes for CVE-2024-37079 and related vCenter Server vulnerabilities, including another critical DCERPC heap overflow. The flaws could be triggered via crafted network packets and exposed unpatched vCenter deployments to possible remote code execution.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

45 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.