CVE-2024-37079Active Exploitation(vmware / cloud_foundation)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch vmware cloud_foundation systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-13. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • vcenter_server

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 13 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 17 signals
  • General: 2 classified signals
  • Peaked 11d ago at 4 mentions (2026-01-28); latest day: 3
  • 24 total mentions across 13 days

Affected systems

Vendors
Products
cloud_foundationvcenter_server

2 versions affected across 2 products

Deep dive

Activity timeline24 mentions / 13d
01234Mentions · 2026-01-27: 3Mentions · 2026-01-28: 4Mentions · 2026-01-29: 3Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Mentions · 2026-02-02: 1Mentions · 2026-02-04: 1Mentions · 2026-02-05: 2Mentions · 2026-02-07: 1Mentions · 2026-02-23: 1Mentions · 2026-02-25: 2Mentions · 2026-03-11: 1Mentions · 2026-05-04: 3PoC Mentioned / Linked · 2026-01-31: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-27: 3Active Exploitation · 2026-01-28: 2Active Exploitation · 2026-01-29: 3Active Exploitation · 2026-01-30: 1Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-02-05: 2Active Exploitation · 2026-02-07: 1Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-25: 2Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-05-04: 2Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-29: 3Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-01-31: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-05: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-01-27: 3Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 1Technical Details · 2026-01-31: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-11: 1Technical Details · 2026-05-04: 201-2701-2801-2901-3001-3102-0202-0402-0502-0702-2302-2503-1105-04
Signal classification3 categories
Active Exploitation
1979.2%
Patch
312.5%
General
28.3%
Referenced assets40 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-273
Active Exploitation3
2026-01-284
Active Exploitation2General1Patch1
2026-01-293
Active Exploitation2Patch1
2026-01-301
Active Exploitation1
2026-01-311
Active Exploitation1
2026-02-021
Active Exploitation1
2026-02-041
Patch1
2026-02-052
Active Exploitation2
2026-02-071
Active Exploitation1
2026-02-231
Active Exploitation1
2026-02-252
Active Exploitation2
2026-03-111
Active Exploitation1
2026-05-043
Active Exploitation2General1
Full discourse20 posts
  • Sami Laiho@samilaiho
    Active Exploitation

    I'm getting more and more contacts about this being actively used, so patch, patch, patch! VMSA-2024-0012:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081) #broadcom #vmware https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/securityadvisories/0/24453

    Post summary

    The message conveys reports of active exploitation of CVE‑2024‑37079/80/81 and urges immediate patching through the VMware vCenter Server update.

    010911.2K
    30.4K followersView on X
  • Günter Born@etguenni
    Active Exploitation

    Uralte Schwachstellen aus 2024 werden wohl in VMware vCenter Server angegriffen https://borncity.com/blog/2026/02/25/angriffe-auf-vmware-vcenter-server-schwachstellen-cve-2024-37079-cve-2024-37080-cve-2024-37081/

    Post summary

    The post indicates that CVE-2024-37079, CVE-2024-37080, and CVE-2024-37081 in VMware vCenter Server are reportedly being targeted in the wild, but no exploit details or patches are provided.

    01051288
    2.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    CISA orders patching of VMware vCenter critical RCE flaw (CVE-2024-37079) after June DCERPC heap-overflow fix. 1Password adds phishing alerts as AI phishing rises. Microsoft fixes Windows 11 boot issues with KB5074109. #VMware #US #PhishingProtection https://ift.tt/cph5m6B

    Post summary

    CISA mandates patching for VMware vCenter CVE‑2024‑37079, Microsoft issues a Windows 11 boot fix, and 1Password adds phishing alerts.

    00030578
    3.6K followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    Active Exploitation

    VMware by Broadcom has confirmed in-the-wild exploitation of CVE-2024-37079 in VMware vCenter Server, and CISA has flagged it as actively exploited with a hard remediation deadline for U.S. federal agencies of February 13, 2026. That combination (vendor confirmation + KEV-style urgency + ransomware chatter) is the signal: attackers aren’t testing this anymore, they’re operationalizing it. Continue reading at https://angrysysops.com/2026/02/05/vcenter-server-cve-2024-37079-is-now-getting-weaponized-in-ransomware-campaigns-patch-like-you-mean-it/ | Angry Admin

    Post summary

    VMware confirms CVE-2024-37079 is being actively exploited in the wild, with CISA designating it as a KEV and urging urgent remediation.

    01010144
    479 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    CISA adds CVE-2024-37079, a critical heap-overflow RCE in VMware vCenter Server, to its KEV catalog after confirming active exploitation. The flaw enables unauthenticated remote code execution and lateral movement. #VMwareFlaw #RemoteCodeExec #USA https://ift.tt/9FThBAX

    Post summary

    CISA reports that CVE-2024-37079, a heap-overflow RCE in VMware vCenter Server, is actively being exploited in the wild.

    00011132
    3.6K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2024-37079 to the Known Exploited Vulnerabilities catalog on 2026-01-23, flagging active exploitation and mandating federal remediation timelines CISA KEV. The vulnerability is an out-of-bounds write in Broadcom VMware vCenter Server’s…

    Post summary

    CISA has listed CVE-2024-37079 as an actively exploited vulnerability, triggering federal remediation orders, and the flaw is an out‑of‑bounds write in Broadcom VMware vCenter Server.

    1000041
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-37079: Out-of-bounds write in vCenter Server’s DCERPC implementation enables network-triggered RCE; CISA added CVE-2024-37079 to the KEV on 2026-01-23.

    Post summary

    CISA’s inclusion of CVE‑2024‑37079 on its KEV list highlights a high‑risk, network‑triggered RCE flaw in vCenter Server’s DCERPC, indicating active or imminent exploitation potential.

    1000046
    152 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/01/23:VMware:vCenter の脆弱性 CVE-2024-37079 を登録 https://iototsecnews.jp/2026/01/24/cisa-adds-actively-exploited-vmware-vcenter-flaw-cve-2024-37079-to-kev-catalog/ 仮想化環境の管理を担う VMware vCenter Server において、外部からシステムを完全に乗っ取られる恐れのある深刻な脆弱性が、現在進行形で攻撃に悪用されていることが確認されました。この問題の原因は、vCenter Serverが通信で使用する DCE/RPC プロトコルの処理プログラムに、メモリ管理の不備であるヒープ・オーバーフローが存在していた点にあります。 この脆弱性 CVE-2024-37079 は、最大級の深刻度を示す CVSS スコア 9.8 と評価されています。攻撃者は、ネットワーク経由で細工したパケットを送信するだけで、パスワードなどの認証なしに、サーバ上で任意のプログラムの実行を引き起こせます。さらに、他の脆弱性と組み合わせることで、最高権限である root 権限を奪い、最終的には管理下の仮想マシンが動く ESXiホスト 全体の制御の奪取を可能にします。ご利用のチームは、ご注意ください。 #CISA #CVE202437079 #Exploit #Government #KEV #vCenterServer #VMware #Vulnerability

    Post summary

    CISA’s KEV warning confirms that CVE‑2024‑37079 in VMware vCenter is being actively exploited in the wild, enabling remote code execution through a heap‑overflow flaw in DCE/RPC.

    01000153
    483 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Emergency patches released for Microsoft Office zero-day CVE-2026-21509 and VMware vCenter flaw CVE-2024-37079 exploited in the wild. Dormakaba door access flaws, Stanley malware, Nike data breach, and Sandworm attacks on Poland's power grid also reporte… https://ift.tt/Auhgql6

    Post summary

    The tweet reports that emergency patches have been released for two zero‑day CVEs and notes that one of them is being exploited in the wild, emphasizing the urgency of applying the fixes.

    00010919
    3.6K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    VMware vCenter Serverの1年前の脆弱性(CVE-2024-37079)がKEVに追加 https://rocket-boys.co.jp/security-measures-lab/vmware-vcenter-server-one-year-old-vulnerability-added-to-kev-cve-2024-37079/ #セキュリティ対策Lab #セキュリティ #Security #サイバー攻撃 #CybersecurityNews

    Post summary

    The article announces that the one‑year‑old CVE‑2024‑37079 for VMware vCenter Server has been added to the KEV list, but does not provide additional technical, exploit, or mitigation details.

    01000144
    318 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/active-exploit-cve-2024-37079-vmware-vcenter-server #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content merely cites a URL and hashtags with no substantive details about the CVE, its exploitation status, or mitigation steps.

    0000021
    152 followersView on X
  • RagingCISO@CisoRaging77913
    Active Exploitation

    CVE-2024-37079: VMware vCenter heap overflow. One unauthenticated network packet → RCE. Actively exploited. The nerve center of your virtualization owned by a single crafted packet. Broadcom confirms ITW. Patch or pray—attackers already have admin on your hypervisors.

    Post summary

    CVE-2024-37079 is a VMware vCenter heap overflow that is being actively exploited via a single unauthenticated packet; patches are advised to prevent attackers from gaining hypervisor admin.

    0000024
    5 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day | 24-02-2026 Source: https://www.recordedfuture.com/blog/january-2026-cve-landscape Key details below ↓ 🧑‍💻Actors/Campaigns: Fancy_bear Neusploit 💀Threats: Nuclei_tool, Minidoor, Pixynetloader, Covenant_c2_tool, Grunt, Com_hijacking_technique, Supply_chain_technique, 🎯Victims: Enterprise communication platforms, Enterprise management platforms, Government users, Business users, Wordpress sites, Email systems 🏭Industry: Government 🌐Geo: Russian 🔓CVEs: CVE-2026-23760 \[[Vulners](https://vulners.com/cve/CVE-2026-23760)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-34026 \[[Vulners](https://vulners.com/cve/CVE-2025-34026)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - versa-networks concerto (<12.1.2, 12.2.0) CVE-2009-0556 \[[Vulners](https://vulners.com/cve/CVE-2009-0556)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft office_powerpoint (2004) - microsoft powerpoint (2000, 2002, 2003) CVE-2025-8110 \[[Vulners](https://vulners.com/cve/CVE-2025-8110)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - gogs (le0.13.3) CVE-2026-24423 \[[Vulners](https://vulners.com/cve/CVE-2026-24423)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9511) CVE-2025-68645 \[[Vulners](https://vulners.com/cve/CVE-2025-68645)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - synacor zimbra_collaboration_suite (<10.0.18, <10.1.13) CVE-2018-14634 \[[Vulners](https://vulners.com/cve/CVE-2018-14634)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - paloaltonetworks pan-os (<7.1.23, <8.0.16, <8.1.7) CVE-2026-21509 \[[Vulners](https://vulners.com/cve/CVE-2026-21509)] - CVSS V3.1: *7.8*, - Vulners: Exploitation: True Soft: - microsoft 365_apps (-) - microsoft office (2016, 2019) - microsoft office_long_term_servicing_channel (2021, 2024) CVE-2025-37164 \[[Vulners](https://vulners.com/cve/CVE-2025-37164)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - hpe oneview (le10.20.00) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2026-20045 \[[Vulners](https://vulners.com/cve/CVE-2026-20045)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - cisco unified_communications_manager (<14su5, le15su3a) - cisco unified_communications_manager_im_and_presence_service (<14su5, le15su3a) - cisco unity_connection (<14su5, le15su3) CVE-2026-20931 \[[Vulners](https://vulners.com/cve/CVE-2026-20931)] - CVSS V3.1: *8.0*, - Vulners: Exploitation: Unknown Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2026-20805 \[[Vulners](https://vulners.com/cve/CVE-2026-20805)] - CVSS V3.1: *5.5*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1607 (<10.0.14393.8783) - microsoft windows_10_1809 (<10.0.17763.8276) - microsoft windows_10_21h2 (<10.0.19044.6809) - microsoft windows_10_22h2 (<10.0.19045.6809) ... CVE-2025-52691 \[[Vulners](https://vulners.com/cve/CVE-2025-52691)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - smartertools smartermail (<100.0.9413) CVE-2025-31125 \[[Vulners](https://vulners.com/cve/CVE-2025-31125)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - vitejs vite (<4.5.11, <5.4.16, <6.0.13, <6.1.3, <6.2.4) CVE-2026-24858 \[[Vulners](https://vulners.com/cve/CVE-2026-24858)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortianalyzer (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortimanager (le7.0.15, le7.2.11, <7.4.10, <7.6.6) - fortinet fortiproxy (le7.0.22, le7.2.15, le7.4.12, le7.6.4) - fortinet fortiweb (le7.4.11, le7.6.6, le8.0.3) ... CVE-2025-54313 \[[Vulners](https://vulners.com/cve/CVE-2025-54313)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - prettier eslint-config-prettier (8.10.1, 9.1.1, 10.1.6, 10.1.7) CVE-2025-40551 \[[Vulners](https://vulners.com/cve/CVE-2025-40551)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - solarwinds web_help_desk (<2026.1) CVE-2026-20029 \[[Vulners](https://vulners.com/cve/CVE-2026-20029)] - CVSS V3.1: *4.9*, - Vulners: Exploitation: Unknown CVE-2026-23550 \[[Vulners](https://vulners.com/cve/CVE-2026-23550)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2026-23800 \[[Vulners](https://vulners.com/cve/CVE-2026-23800)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: Unknown CVE-2024-37079 \[[Vulners](https://vulners.com/cve/CVE-2024-37079)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - vmware cloud_foundation (<5.2) CVE-2026-24061 \[[Vulners](https://vulners.com/cve/CVE-2026-24061)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - gnu inetutils (le2.7) 🤖LLM extracted TTPs:` T1005, T1027, T1053.005, T1071.001, T1078, T1090, T1098, T1112, T1114.003, T1133, ... 🧨IOCs: - Path: 2 - Registry: 1 - IP: 6 - Email: 4 - File: 2 💽Software: Microsoft Office, Ivanti, Linux, Zimbra Collaboration Suite, WordPress, Outlook, Ivanti EPMM 🔢Algorithms: xor 📜Programming Languages: php #threatreport: In January 2026, there was a noted 5% increase in critical vulnerabilities, with 23 high-impact issues identified. Among these, the exploitation of a significant Microsoft Office zero-day vulnerability (CVE-2026-21509) by Russian state-sponsored group APT28 highlighted ongoing threats to enterprise technologies. This vulnerability, which relates to the reliance on untrusted inputs in security decisions, enabled APT28 to utilize weaponized Rich Text Format (RTF) files to deliver various malicious implants, including MiniDoor, PixyNetLoader, and Covenant Grunt. The exploitation chain initiated with an RTF file that bypassed Office OLE mitigations. The attackers deployed MiniDoor as an Outlook VBA script for email collection, while PixyNetLoader, which created a mutex for persistence, allowed further attacks. A notable aspect of this operation was the use of geography-based evasion to limit the delivery of the malicious payloads, demonstrating the sophistication of the APT28 attacks. In addition to Microsoft, other vendors such as SmarterTools and Ivanti were significantly affected, with SmarterTools reporting multiple critical vulnerabilities allowing authentication bypass and remote code execution (RCE). Specifically, CVE-2026-23760 identified a privilege escalation flaw in SmarterMail, permitting unauthenticated users to reset passwords, demonstrating serious flaws in expected security protocols. Furthermore, the Modular DS WordPress plugin was found to have multiple vulnerabilities, CVE-2026-23550 and CVE-2026-23800, that allowed attackers to gain administrator access without authentication. These vulnerabilities emphasize the risk of widespread exploitation due to the centralized management of multiple WordPress sites.

    Post summary

    The report details active exploitation of CVE-2026-21509 by APT28 using weaponized RTF files and associated tools, highlighting ongoing threats to enterprise systems.

    0000074
    589 followersView on X
  • Fortexa@FortexaAU
    Active Exploitation

    @VMware vCenter just hit CISA's KEV list. If you're running virtual infrastructure and haven't patched CVE-2024-37079, attackers can write to memory they shouldn't touch. That's every VM, every workload, every app. How fast can you move when your entire data center is the target?

    Post summary

    CVE-2024-37079 is listed on CISA's KEV, indicating that VMware vCenter is being actively exploited for unauthorized memory writes across virtual workloads, and users must patch immediately.

    0000051
    2 followersView on X
  • TheTechWorldPodcast@TheTechWorldPod
    Active Exploitation

    🚨 vCenter under attack. CVE-2024-37079 is now actively exploited in ransomware campaigns. One unpatched vCenter = full virtual estate at risk. If it’s still on your “later” list, later is too late. Patch. Verify. Lock it down. 🔐 https://angrysysops.com/2026/02/05/vcenter-server-cve-2024-37079-is-now-getting-weaponized-in-ransomware-campaigns-patch-like-you-mean-it/ #VMware #CyberSecurity #Ransomware #vCenter #InfoSec #vExpert @vExpert

    Post summary

    CVE‑2024‑37079 is being actively exploited in ransomware campaigns, and users are urged to patch immediately.

    00000112
    479 followersView on X
  • Phanera@phaneragnosis
    Patch

    🚨 vCenter Server CVE-2024-37079: ITW DCERPC heap-o/f → net RCE. Exposed: reachable vCenter 7/8 + VCF. Patch: 8.0U2d/8.0U1e/7.0U3r (VCF KB88287). If not patched now: firewall vCenter to admin IPs only. https://www.cyber.gc.ca/en/alerts-advisories/vmware-security-advisory-av24-345

    Post summary

    The advisory announces that CVE‑2024‑37079, a heap‑based RCE in VMware vCenter, is being exploited in the wild and provides specific patch versions and a firewall mitigation recommendation.

    0000072
    12 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    📡 𝗡𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿 Podcast 𝗥𝗮𝗱𝗶𝗼𝗖𝗦𝗜𝗥𝗧 𝗻°𝟰𝟳 | 𝗦𝗲𝗺𝗮𝗶𝗻𝗲 𝗱𝘂 𝟮𝟰 𝗮𝘂 𝟯𝟬 𝗷𝗮𝗻𝘃𝗶𝗲𝗿 𝟮𝟬𝟮𝟲 Récapitulatif des épisodes 558 à 564 du podcast quotidien RadioCSIRT. 𝗩𝘂𝗹𝗻𝗲́𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝗲́𝘀 𝗰𝗿𝗶𝘁𝗶𝗾𝘂𝗲𝘀 𝗲𝘁 𝗞𝗘𝗩 CVE-2026-21962 (Oracle) : PoC publié 24h après le patch CVE-2024-37079 (VMware vCenter, CVSS 9.8) : exploitation par 3 APT chinois confirmée CVE-2026-24061 (GNU InetUtils telnetd) : 800K serveurs exposés, exploitation active CVE-2026-21509 (Microsoft Office) : zero-day exploité activement CVE-2026-24858 (Fortinet) : contournement authentification SSO FortiCloud 𝗖𝗼𝗿𝗿𝗲𝗰𝘁𝗶𝗳𝘀 𝗱'𝘂𝗿𝗴𝗲𝗻𝗰𝗲 Microsoft KB5078127 : seconde mise à jour hors-bande en une semaine SolarWinds Web Help Desk : 6 vulnérabilités dont 4 critiques (RCE non authentifiée) 6000+ serveurs SmarterMail exposés (CVE-2025-52691, CVE-2026-23760) 𝗠𝗲𝗻𝗮𝗰𝗲𝘀 𝗮𝗰𝘁𝗶𝘃𝗲𝘀 DynoWiper (Sandworm) : attaque secteur énergétique polonais Kimwolf : 2M+ dispositifs IoT infectés, présence dans 25% réseaux corporate UAT-8099 (Chine) : ciblage serveurs Microsoft IIS 𝗜𝗻𝗰𝗶𝗱𝗲𝗻𝘁 𝗢𝗣𝗦𝗘𝗖 Directeur par intérim CISA : exfiltration involontaire documents classifiés via ChatGPT 𝗡𝗲𝘄𝘀𝗹𝗲𝘁𝘁𝗲𝗿 𝗰𝗼𝗺𝗽𝗹𝗲̀𝘁𝗲 𝗱𝗶𝘀𝗽𝗼𝗻𝗶𝗯𝗹𝗲 𝗶𝗰𝗶 : https://radiocsirt.substack.com/p/newsletter-radiocsirt-n47?r=57c3ye #Cybersecurity #ThreatIntelligence #CERT #CSIRT #InfoSec

    Post summary

    The newsletter highlights several newly disclosed CVEs that are currently being actively exploited by threat actors, with available patches, workarounds, and PoC references for at least one vulnerability.

    00000131
    414 followersView on X
  • The Sovereign Protocol@sovereignexec
    Active Exploitation

    ALERT: VMware vCenter RCE exploit (CVE-2024-37079) actively weaponized by threat actors. SOVEREIGN PROTOCOL: Immediate network segmentation of virtualization infrastructure, deploy dedicated management VLANs, implement zero-trust access controls. #TheSovereignProtocol

    Post summary

    VMware vCenter RCE CVE-2024-37079 is actively weaponized; immediate network segmentation and zero‑trust controls are recommended.

    0000082
    4 followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    CISA says critical VMware RCE flaw now actively exploited Patched in June 2024, this security flaw (CVE-2024-37079) stems from a heap overflow weakness in the DCERPC protocol implementation of vCenter Server (a Broadcom VMware vSphere management platform that helps admins manage ESXi hosts and virtual machines). https://nuel.ink/vpXj0b

    Post summary

    CISA reports that the CVE-2024-37079 VMware RCE, caused by a heap overflow in DCERPC, is being actively exploited, and a patch was released in June 2024.

    0000093
    1.1K followersView on X
  • The Sovereign Protocol@sovereignexec
    Active Exploitation

    CISA confirms active exploitation of critical VMware vCenter RCE flaw CVE-2024-37079. Threat actors achieve remote code execution via crafted network packets. Sovereign Protocol: Immediately audit all virtualization infrastructure, implement network segmentation, deploy endpoint detection on hypervisor hosts, and establish air-gapped backup systems. Enterprise infrastructure compromise enables total data exfiltration and operational disruption. #TheSovereignProtocol

    Post summary

    CISA confirms that VMware vCenter RCE flaw CVE-2024-37079 is actively exploited via crafted network packets; mitigation includes network segmentation, endpoint detection, and air-gapped backups.

    0000067
    4 followersView on X
CPE platform detail44 entries

44 of 44 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--

Explore more