CVE-2026-47876
CRITICAL · 9.3 EPSS 0.3%Vendor advisory public with patches; no PoC/KEV yet; strong defender urgency signal.
What: Out-of-bounds write in VMware ESXi VMXNET3 virtual network adapter enabling VM escape; affects ESX, vCenter, Workstation, and Fusion (CVSS critical, up to 9.8).
Why it matters: Vendor advisory (VMSA-2026-0006) published with patches available; critical severity and VM escape class warrant immediate remediation. No public PoC or in-the-wild exploitation confirmed yet, but urgency messaging from security outlets and vendors signals active patch deployment phase.
Where it's seen: SecurityWeek and IT-Connect coverage, vendor advisory aggregation on Vulnerability-Lookup, repeated social emphasis on "patch urgency" and bundled advisory. Moderate engagement across Bluesky infosec accounts; inclusion in top CVEs for the week.
RISK: CRITICAL — VM escape in widely deployed hypervisor; vendor patched; CVSS 9.8; immediate exploitation risk if unpatched.
Description
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
CVSS 3.1 breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Local
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High