Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-47876: VMware ESX VMXNET3 Network Adapter Security Risk

CVE-2026-47876 · published 2 months ago
Summary

A critical security risk exists in VMware ESX's VMXNET3 network adapter. An attacker with local administrative access to a virtual machine using this adapter could potentially take control of the host server. Update VMware ESX to the latest version to mitigate this risk.

What to do
  • Update vmware esx to version ESXi-9.1.0.0200-25557999 or later.
Affected software
VendorProductAffected versions
vmware cloud foundation 9.1.x.x
vmware vsphere foundation 9.1.x.x
vmware esx < ESXi-9.1.0.0200-25557999
vmware telco cloud platform 5.1.x
Original advisory text
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual net...
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Severity
9.3 Critical
CVSS 3.1: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-787Out-of-bounds Write
Timeline
Published30 Jul 2026
Updated27 Sep 2026
First seen30 Jul 2026
Sources
CVE-2026-47876 · MITRE
Track software like this
Free during beta