CVE-2026-47876

Summary

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Affected Software

VendorProductVersion RangeStatus
VMwareCloud Foundation9.1.x.xaffected
VMwareCloud Foundation9.0.x.xaffected
VMwareCloud Foundation5.xaffected
VMwarevSphere Foundation9.1.x.xaffected
VMwarevSphere Foundation9.0.x.xaffected
VMwareESX9.1.x.x < ESXi-9.1.0.0200-25557999affected
VMwareESX9.0.x.x < ESXi-9.0.2.0100-25595025affected
VMwareESX8.0 < ESXi80U3k-25595708affected
VMwareTelco Cloud Platform5.1.xaffected
VMwareTelco Cloud Platform5.0.xaffected

Weaknesses

  • CWE-787: CWE-787 Out-of-bounds write

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References