The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged a critical VMware vCenter Server vulnerability as actively exploited and ordered federal agencies to secure their servers within three weeks. Patched in June 2024, this security flaw (CVE-2024-37079) stems from a heap overflow weakness in the DCERPC protocol implementation of vCenter Server (a Broadcom VMware vSphere management platform that helps admins manage ESXi hosts and virtual machines). Threat actors with network access to vCenter Server may exploit this vulnerability by sending a specially crafted network packet that can trigger remote code execution in low-complexity attacks that don't require privileges on the targeted systems or user interaction. There are no workarounds or mitigations for CVE-2024-37079, so Broadcom advised customers to apply security patches to the latest vCenter Server and Cloud Foundation releases as soon as possible. On Friday, CISA added the vulnerability to its catalog of flaws exploited in the wild, giving Federal Civilian Executive Branch (FCEB) agencies three weeks to secure vulnerable systems by February 13th, as mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021. FCEB agencies are non-military U.S. executive branch agencies, such as the Department of State, the Department of Justice, the Department of Energy, and the Department of Homeland Security. "This type of vulnerability is a frequent attack vector for malicious cyber acto...
CISA says critical VMware RCE flaw now actively exploited
BleepingComputer
·Sergiu Gatlan
·Published Jan 26, 2026
·Updated
Affected Software
5 affected components
Broadcom VMware vCenter Server<=latest
Broadcom VMware Cloud Foundation<=latest
Broadcom VMware Aria Operations<=latest
Broadcom VMware Tools<=latest
Broadcom Vmware Nsx<=latest
Frequently Asked Questions
1
What is the critical vulnerability mentioned in the article?
The article discusses a critical remote code execution (RCE) vulnerability in VMware vCenter Server.
2
Which federal agency has issued a warning about the VMware vulnerability?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued the warning.
3
What action has CISA ordered federal agencies to take concerning the VMware vulnerability?
CISA has ordered federal agencies to secure their servers within three weeks.
4
What specific VMware products are affected by this vulnerability?
The vulnerability affects VMware vCenter Server, VMware Cloud Foundation, VMware Aria Operations, VMware Tools, and VMware NSX.
5
When was the vulnerability initially patched?
The vulnerability was patched in June 2024.