A U.S. cybersecurity agency has added a high-severity VMware vulnerability to its catalog due to active exploitation. The flaw allows unauthenticated attackers to execute arbitrary commands for potential remote code execution. Patches and a temporary workaround are available for affected products. Federal agencies are mandated to apply fixes by a specific deadline. The article covers the vulnerability's details, the response from authorities and the vendor, and the current lack of information on the exploitation campaigns.