CVE-2026-47876: VMware ESXi VM Escape Flaw

CVE-2026-47876: VMware ESXi VM Escape Flaw

Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter.

Successful exploitation requires the attacker to already have local administrative privileges inside a guest virtual machine configured with VMXNET3. From that position, the attacker can trigger an out-of-bounds write and cross the isolation boundary between the guest and the ESX host.

This VM Escape Vulnerability is particularly serious in multi-tenant, cloud, and enterprise virtualization environments. Compromise of the hypervisor can expose other virtual machines, management data, application workloads, and infrastructure secrets located on the same host.

Broadcom has found no evidence that the flaw has been exploited in the wild. However,…