Tag

Vcenter

All articles tagged with #vcenter

Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence
security2 hours ago

Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence

A critical vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to install the open-source reverse_ssh tool, establishing a persistent outbound C2 channel for remote access. Across 47 countries, 361 victim IPs have been identified, with Germany, the U.S., Turkey, Iran, and France most affected. VMware released an emergency patch; there are no official workarounds. Researchers from QUIRSO suspect an advanced persistent threat behind the campaign and note the attackers' activity began days after the vulnerability disclosure.

CISA Tightens Patch Deadline for Actively Exploited VMware vCenter RCE
technology6 months ago

CISA Tightens Patch Deadline for Actively Exploited VMware vCenter RCE

CISA warns that the actively exploited VMware vCenter Server remote-code-execution flaw CVE-2024-37079 is being used in the wild and orders U.S. federal agencies to patch within three weeks, citing a DCERPC heap overflow that enables easy remote control with no user interaction. Broadcom notes there are no mitigations, advising immediate patches to the latest vCenter Server and Cloud Foundation releases.

CISA Flags VMware vCenter RCE Flaw CVE-2024-37079 as Actively Exploited
security6 months ago

CISA Flags VMware vCenter RCE Flaw CVE-2024-37079 as Actively Exploited

CISA added CVE-2024-37079, a critical heap-overflow flaw in Broadcom VMware vCenter Server, to the KEV catalog after evidence of active exploitation; Broadcom patched CVE-2024-37079 (and CVE-2024-37080) in June 2024, with researchers Hao Zheng and Zibo Li linking related DCE/RPC flaws; a Black Hat Asia 2025 presentation notes two additional CVEs (CVE-2024-38812/38813) patched later, and federal agencies must upgrade to the latest version by Feb 13, 2026 to stay protected.