VMware’s vCenter Server has two critical vulnerabilities (CVE-2024-38812 and CVE-2024-38813), both actively exploited in the wild. CVE-2024-38812 allows remote code execution via a heap overflow, while CVE-2024-38813 enables privilege escalation. VMware issued initial patches in September, but further updates were required due to incomplete fixes. Administrators should apply the latest patches immediately to mitigate these risks.