


Perceptive Security
SOC/SIEM Consultancy

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a vir…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 14:01:29
Source:
nvd.nist.gov
Cloud & Virtualization, Zero-Day Vulnerabilities
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine using the VMXNET3 adapter can exploit this vulnerability to execute arbitrary code on the host system. This represents a guest-to-host escape scenario, which is considered high severity in virtualization environments. Only virtual machines using the VMXNET3 adapter are affected; other virtual network adapter types are not impacted. The vulnerability has been assigned CVE-2026-47876 and is tracked by NVD and Broadcom security advisories.
Technical details
Mitigation steps:
Affected products:
VMware ESX
VMXNET3 virtual network adapter
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47876
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
