Out-of-Bounds Write Vulnerability in VMware ESX VMXNET3 Network Adapter
CVE-2026-47876

9.3CRITICAL

Key Information:

Vendor

Vmware

Vendor
CVE Published:
30 July 2026

What is CVE-2026-47876?

VMware ESX is vulnerable due to an out-of-bounds write issue related to the VMXNET3 virtual network adapter. If an attacker gains local administrative privileges on a virtual machine utilizing this adapter, they may exploit the vulnerability to execute arbitrary code on the host system. Importantly, virtual machines using non-VMXNET3 network adapters are not impacted by this vulnerability, highlighting the need for system administrators to ensure secure configurations and monitoring.

Affected Version(s)

Cloud Foundation 9.1.x.x

Cloud Foundation 9.0.x.x

Cloud Foundation 5.x

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.