SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47876

CRITICAL · CVSS 9.3 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

VMware ESX is vulnerable due to an out-of-bounds write flaw in the VMXNET3 virtual network adapter, which can be exploited by a local administrator on a virtual machine to execute arbitrary code on the host system. This critical vulnerability poses a significant risk to environments utilizing VMXNET3, and organizations using VMware products should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47876
Severity
CRITICAL
CVSS
9.3
EPSS
0.36%
VMware VMWare

Original NVD Description

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.