Vulnerability intelligence
CVE-2024-37079
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability
Broadcom VMware vCenter Server
Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.
CVSS Score
—
Unrated
EPSS — Exploit Probability
22%
Riskier than 98% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
KEV since 2026-01-23
Remediation
Unconfirmed
Federal deadline 2026-02-13
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-02-13.
5 articles across 4 outlets · first covered Jan 24, 2026 · latest Jan 26, 2026
Coverage timeline
-
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & Morethehackernews.com · Jan 26, 2026
-
2024 VMware Flaw Now in Attackers’ Crosshairswww.securityweek.com · Jan 26, 2026
-
CISA Alert: Critical VMware vCenter RCE (CVSS 9.8) Now Exploited in the Wildsecurityonline.info · Jan 25, 2026
-
U.S. CISA adds a flaw in Broadcom VMware vCenter Server to its Known Exploited Vulnerabilities catalogsecurityaffairs.com · Jan 24, 2026
-
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalogthehackernews.com · Jan 24, 2026