---
title: "CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog"
url: https://daily.dev/posts/cisa-adds-actively-exploited-vmware-vcenter-flaw-cve-2024-37079-to-kev-catalog-rkbcyw2zw
source_url: https://thehackernews.com/2026/01/cisa-adds-actively-exploited-vmware.html
type: article
source: "The Hacker News"
published: 2026-01-24T08:41:24.711Z
updated: 2026-02-28T04:31:39.311Z
tags: ["security", "cyber", "vulnerability", "vmware"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog

**[The Hacker News](https://daily.dev/sources/thn)** · 2 min read · 0 upvotes · 0 comments

## Summary

CISA added VMware vCenter Server vulnerability CVE-2024-37079 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The critical flaw (CVSS 9.8) is a heap overflow in the DCE/RPC protocol implementation that enables remote code execution via specially crafted network packets. Originally patched by Broadcom in June 2024, the vulnerability can be chained with other flaws to achieve unauthorized root access to ESXi. Federal agencies must apply patches by February 13, 2026.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/cisa-adds-actively-exploited-vmware.html>

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#vulnerability](https://daily.dev/tags/vulnerability), [#vmware](https://daily.dev/tags/vmware)

[View this post on daily.dev](https://daily.dev/posts/cisa-adds-actively-exploited-vmware-vcenter-flaw-cve-2024-37079-to-kev-catalog-rkbcyw2zw)
