Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 13, 2026

CVE-2024-37079

High
EPSS 82.7%CISA KEV
Broadcom/VMware vCenter Server

Description

Broadcom VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. This could allow a malicious actor with network access to vCenter Server to send specially crafted network packets, potentially leading to remote code execution.

EPSS — Exploit Probability

82.7%

Higher than 99.2% of all CVEs

Required Action

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453 ; https://nvd.nist.gov/vuln/detail/CVE-2024-37079

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
82.7%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jan 23, 2026

Added to KEV

Jan 23, 2026

Remediation Due

Feb 13, 2026

Affected Product

Broadcom

VMware vCenter Server

View all Broadcom CVEs