CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution
ID: 2cfa5a9d-b6ac-5346-8192-28f94d62464b
STIX ID: report--2cfa5a9d-b6ac-5346-8192-28f94d62464b
Feed Name: SOC Prime Blog
Broadcom released emergency security updates for CVE-2026-47876, a critical (CVSS 9.3) out-of-bounds write in the VMXNET3 virtual network adapter on VMware ESX that allows a guest with administrative privileges to escape to and execute code on the hypervisor; affected ESX branches and fixed build numbers are listed, there are no effective workarounds, no public proof-of-concept or evidence of in-the-wild exploitation, and organizations are urged to apply the emergency patches and follow the provided detection and incident-response guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
