Broadcom VMware vCenter Server and Cloud Foundation patch advisory (CVE-2024-37079)
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Broadcom told customers to apply security patches for CVE-2024-37079 in vCenter Server and Cloud Foundation, after the flaw was tied to active exploitation and remote code execution risk. The company said there are no workarounds or mitigations, making patching the only vendor-backed remediation. Broadcom urged customers to update the latest releases as soon as possible.
Related Happenings
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
Broadcom VMware Avi Load Balancer security update release
Security Patch Release
H score26
First: 14.07.2026 16:55
Last: 14.07.2026 16:55
Sources 1
About this happening:
Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...
Broadcom VMware Avi Load Balancer security update release
Security Patch ReleaseAbout this happening: Broadcom released VMware Avi Load Balancer updates that patch seven potentially serious vulnerabilities, including authentication bypass, remote code execution...
Apple security patch release for CVE-2025-20701
Security Patch Release
H score29
First: 18.06.2026 15:23
Last: 18.06.2026 15:23
Sources 1
About this happening:
Apple released Beats Firmware Update 1B211 for Beats Studio Buds to fix CVE-2025-20701, closing a Bluetooth flaw that could let nearby attackers spy on conversations....
Apple security patch release for CVE-2025-20701
Security Patch ReleaseAbout this happening: Apple released Beats Firmware Update 1B211 for Beats Studio Buds to fix CVE-2025-20701, closing a Bluetooth flaw that could let nearby attackers spy on conversations....
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch Release
H score55
First: 22.05.2026 08:36
Last: 22.05.2026 08:36
Sources 1
About this happening:
Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Cisco Secure Workload REST API patch release (CVE-2026-20223)
Security Patch ReleaseAbout this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Timeline
-
26.01.2026 13:49 2 articles · 5mo ago
Broadcom urges patching for CVE-2024-37079
Mitigation Patch UpdateBroadcom advised customers to install the latest vCenter Server and Cloud Foundation security patches for CVE-2024-37079 after confirming exploitation in the wild and noting that no workarounds or mitigations are available. The flaw is a heap overflow in the DCERPC protocol implementation of vCenter Server and can enable remote code execution through a specially crafted network packet.
Show sources
- CISA says critical VMware RCE flaw now actively exploited — www.bleepingcomputer.com — 26.01.2026 13:49
- CISA says critical VMware RCE flaw now actively exploited — www.bleepingcomputer.com — 26.01.2026 13:49