CVE-2024-37080Active Exploitation(vmware / cloud_foundation)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch vmware cloud_foundation systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_foundation
  • vcenter_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
cloud_foundationvcenter_server

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-23: 1Mentions · 2026-02-25: 1Active Exploitation · 2026-02-23: 1Active Exploitation · 2026-02-25: 1Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-23: 102-2302-25
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Sami Laiho@samilaiho
    Active Exploitation

    I'm getting more and more contacts about this being actively used, so patch, patch, patch! VMSA-2024-0012:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081) #broadcom #vmware https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/securityadvisories/0/24453

    Post summary

    The advisory warns that CVE‑2024‑37079/80/81 are being actively exploited in the wild and urges immediate patching of VMware vCenter Server.

    010911.2K
    30.4K followersView on X
  • Günter Born@etguenni
    Active Exploitation

    Uralte Schwachstellen aus 2024 werden wohl in VMware vCenter Server angegriffen https://borncity.com/blog/2026/02/25/angriffe-auf-vmware-vcenter-server-schwachstellen-cve-2024-37079-cve-2024-37080-cve-2024-37081/

    Post summary

    The post indicates that the 2024 CVEs (37079, 37080, 37081) are being actively exploited against VMware vCenter Server, but no further technical or mitigation details are provided.

    01051288
    2.6K followersView on X
CPE platform detail44 entries

44 of 44 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarecloud_foundation---
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server7.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--
Appvmwarevcenter_server8.0--

Explore more