A critical security advisory has been released regarding Broadcom VMware vCenter. Identifying and addressing vulnerabilities in core infrastructure management tools is essential for maintaining a strong security posture.

### What Happened

Broadcom VMware vCenter contains a path traversal vulnerability. This security flaw could allow a threat actor with network access to vCenter to execute arbitrary code. The issue carries a severity score of high, with a CVSS score of 9.8. Additionally, this vulnerability is tracked on CISA's Known Exploited Vulnerabilities list, meaning active exploitation has been observed in the wild.

You can review specific tracking details on the Korisec CVE tracker page.

### Who Should Care

Small businesses, IT administrators, and organizations using VMware vCenter to manage their virtualized environments should pay close attention to this advisory. Because vCenter often sits at the center of network infrastructure, any flaw that permits arbitrary code execution via network access poses a significant risk to overall operational security and data integrity.

### What to Do Now

When dealing with high-severity infrastructure vulnerabilities, prompt action is necessary to protect your systems. Organizations should take the following steps:

  • Review your environment to identify any instances of VMware vCenter currently in use.
  • Check official vendor channels from Broadcom for the latest security updates and guidance.
  • Restrict network access to vCenter management interfaces to trusted administrative networks only.
  • Monitor logs for unusual activity or unauthorized access attempts.

Staying proactive helps minimize your attack surface and protects critical management assets from potential compromise.

Want to secure your external-facing web assets? Run a free check at Korisec.