The Hacker News
Read post

CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog

CISA added VMware vCenter Server vulnerability CVE-2024-37079 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The critical flaw (CVSS 9.8) is a heap overflow in the DCE/RPC protocol implementation that enables remote code execution via specially crafted network packets. Originally patched by Broadcom in June 2024, the vulnerability can be chained with other flaws to achieve unauthorized root access to ESXi. Federal agencies must apply patches by February 13, 2026.

    #security#cyber#vulnerability#vmware
Jan 24•2m read time•From thehackernews.com
Post cover image
65 Impressions
The Hacker News's image
The Hacker News

The Tidyverse Blog offers insights, tutorials, and updates on the Tidyverse, a collection of R packa...

2.3K Followers

•

1.7K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard