← All Advisories

VMware ESX VMXNET3 Virtual Network Adapter Contains an Out-of-Bounds Write Reachable by a Local VM Admin, Potentially Enabling Code Execution on the Underlying Host

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-47876

Key Details

CVECVE-2026-47876
CVSS Score / Version9.3 (Critical) / CVSS v3.1
Updated2026-07-30
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-787 (Out-of-bounds Write)

What to Know

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-47876
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-47876