What is CVE-2026-47876?
VMware ESX has an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local admin privileges on a VM using VMXNET3 can exploit this to execute code on the host, while other adapters are not affected. Apply the VMware security patch immediately.
Azərbaycanca: VMware ESX-in VMXNET3 virtual şəbəkə adapterində aşkarlanan bu boşluq, lokal inzibati hüquqları olan təcavüzkara hostda kod icrasına imkan verir. Yalnız VMXNET3 adapterindən istifadə edən virtual maşınlar risk altındadır, digər adapterlər təsirlənmir. VMware tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
What level of privileges does an attacker need to exploit CVE-2026-47876?
The attacker must have local admin privileges on a virtual machine that is using the VMXNET3 adapter.
Can CVE-2026-47876 lead to host code execution if a virtual network adapter other than VMXNET3 is used?
No, only virtual machines that are using the VMXNET3 virtual network adapter are at risk; other adapters are not affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.