---
source_url: "https://cyber.gov.rw/updates/article/alert-vmware-security-updates-january-2026/"
title: "National Cyber Security Authority | Alert: VMware Security Updates – January 2026"
mirrored_at: 2026-08-04T15:39:33.186Z
host: cyber.gov.rw
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/cyber.gov.rw/updates/article/alert-vmware-security-updates-january-2026/index"
---

> **Original source:** https://cyber.gov.rw/updates/article/alert-vmware-security-updates-january-2026/

##### VMware has released security updates to address critical vulnerabilities in multiple VMware products, including but not limited to Cloud Foundation and vCenter Server. The most severe is [CVE-2024-37079](https://www.cve.org/CVERecord?id=CVE-2024-37079) (CVSS 9.8), which is actively exploited in the wild.

##### Affected Systems and Versions are:

-   ##### VMware vCenter Server 7.0 (versions prior to patched release)
    
-   ##### VMware vCenter Server 8.0 (versions prior to patched release)
    
-   ##### VMware Cloud Foundation 4.x and 5.x
    

##### **Security Risks**

##### Successful exploitation of these vulnerabilities could allow an attacker to perform local privilege escalation, information disclosure, improper authorization and remote code execution on the targeted system.

##### **Recommended Actions**

##### The National Cyber Security Authority (NCSA) strongly recommends to system administrators to:

-   ##### Follow VMware's security advisory ([Broadcom VMSA-2024-0012](https://support.broadcom.com/web/ecx/security-advisory?)) to lower the risk of potential exploits, protect systems, and ensure their security.
    
-   ##### Upgrade to patched versions: VMware vCenter Server [7.0 Update 3s](https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/7-0/release-notes/vcenter-server-update-and-patch-releases/vsphere-vcenter-server-70u3s-release-notes.html#:~:text=For%20internationalization%2C%20compatibility%2C%20installation%2C,Install%20vCenter%20Server%20Appliance%20Patches.) / [8.0 Update 1e](https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/vcenter-server-update-and-patch-release-notes/vsphere-vcenter-server-80u1e-release-notes.html) (or later)
    

##### Before any update task, please ensure you have a recent backup that can easily be restored.

#####   
For further information and support, please contact NCSA by email at [**rwcsirt@ncsa.gov.rw**](mailto:rwcsirt@ncsa.gov.rw) or call us on **9009**.

##### **References**

-   ##### [Security Advisories - VMware Cloud Foundation](https://support.broadcom.com/web/ecx/security-advisory?)
    
-   ##### [https://www.cve.org/CVERecord?id=CVE-2024-37079](https://www.cve.org/CVERecord?id=CVE-2024-37079)