VMware VM breakout threat patched across ESXi product line

Broadcom shipped emergency patches for a critical VM escape vulnerability affecting VMware ESXi, vCenter, and Fusion products.

CSBadmin
2 Min Read

Broadcom shipped emergency patches for a critical VM escape vulnerability affecting VMware ESXi hypervisors, warning that local attackers inside a virtual machine can break out and execute code on the host system.

Tracked as CVE-2026-47876, the bug lives in the VMXNET3 virtual network adapter and scores a CVSS critical rating. An attacker with local admin rights inside a VM using this adapter can exploit an out-of-bounds write to execute arbitrary code on the ESXi host, effectively escaping the virtual machine boundary.

Broadcom patched the issue alongside four other vulnerabilities across ESXi, vCenter Server, Workstation, and Fusion. Two additional critical flaws affect vCenter: CVE-2026-59309, an authentication bypass granting unauthorized access, and CVE-2026-59310, a remote code execution vector for attackers with network access.

A high-severity flaw, CVE-2026-41703, impacts ESXi, Workstation, and Fusion, allowing users with VM deployment permissions to cause denial of service against the host process. A low-severity logging gap, CVE-2026-41709, lets admins act without being logged.

Broadcom said it has not observed active exploitation of these flaws, but threat actors frequently target VMware products. Organizations running on-premises VMware environments should prioritize patching the VM escape bug given its potential for cross-boundary compromise across tenants sharing a single hypervisor.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.