Signal

CISA adds exploited vmware vCenter flaw to KEV as cisco UC zero-day sees mass scanning

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-01-23 11:47 UTCUpdated 2026-01-24 08:09 UTC
rss
vulnerabilityactive_exploitationvmware_vcentercisco_uckev_catalogpatching
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

Multiple enterprise-facing vulnerabilities are being reported as actively exploited or under active scanning. One track centers on Broadcom VMware vCenter Server, where a previously patched critical flaw is now tied to in-the-wild exploitation and KEV inclusion. Separately, reporting flags mass scanning activity targeting a critical Cisco UC zero-day with takeover potential.

Score total
1.26
Momentum 24h
3
Evidence documents
-
Independent publishers
-
Independent origins
-
Primary sources
-
Secondary sources
-
Source types
-
Duplicate ratio
0%
Why now
  • CISA added CVE-2024-37079 to KEV citing active exploitation in the wild.
  • Reporting says the 2024-patched vCenter bug is being exploited now.
  • Dark Reading reports mass scanning underway for Cisco UC CVE-2026-20045.
Why it matters
  • KEV inclusion signals confirmed exploitation and raises remediation urgency.
  • vCenter Server is a high-value enterprise target; exploitation risk can be outsized.
  • Mass scanning for a critical Cisco UC zero-day increases exposure for reachable systems.
LLM analysis
Topic mix: mediumPromo risk: lowSource quality: high
Recurring claims
  • CISA added CVE-2024-37079 affecting Broadcom VMware vCenter Server to the KEV catalog, citing active exploitation in the wild.
  • A critical VMware vCenter Server bug patched in 2024 is being exploited more than a year later.
  • Mass scanning is underway for Cisco UC CVE-2026-20045, which Cisco tagged as critical because exploitation could lead to complete system takeover.
How sources frame it
  • The Hacker News: neutral
  • The Register: neutral
  • Dark Reading: neutral
Grouped as a single exploitation-focused briefing item: VMware vCenter KEV addition plus separate Cisco UC zero-day scanning report.
All evidence
All evidence
CISA Adds Actively Exploited VMware vCenter Flaw CVE-2024-37079 to KEV Catalog
Thehackernews · thehackernews.com · 2026-01-24 08:09 UTC
Patch or die: VMware vCenter Server bug fixed in 2024 under attack today
Theregister · go.theregister.com · 2026-01-23 22:04 UTC
Exploited Zero-Day Flaw in Cisco UC Could Affect Millions
Darkreading · darkreading.com · 2026-01-23 20:56 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3
Top publishers (this list)
  • Thehackernews (1)
  • Theregister (1)
  • Darkreading (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • go.theregister.com (1)
  • darkreading.com (1)