Broadcom has released emergency patches for CVE-2026-47876, a critical out-of-bounds write flaw in the VMXNET3 virtual network adapter used by VMware ESX environments. The vulnerability, rated CVSS 9.3 and mapped to CWE-787, allows an attacker with local administrator or root privileges inside a guest VM using VMXNET3 to execute code on the underlying host, creating a guest-to-host escape condition. Affected offerings include VMware ESX, VMware Cloud Foundation, VMware vSphere Foundation, and VMware Telco Cloud Platform across specified version ranges.
Broadcom said there is no evidence of active exploitation, no complete workaround, and no published indicators of compromise, increasing pressure on defenders to apply vendor fixes quickly. Security researchers warned that successful exploitation could break VM isolation and expose the hypervisor, adjacent virtual machines, management systems, workloads, and infrastructure secrets, particularly in multi-tenant environments. The flaw was privately reported by Nguyen Hoang Thach of STARLabs SG through Pwn2Own and the Zero Day Initiative, and organizations are being urged to patch affected builds immediately and treat any privileged compromise of a VMXNET3-enabled guest on an unpatched host as a potential hypervisor incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On July 29, 2026, Broadcom published a security advisory and emergency security updates for CVE-2026-47876, a critical out-of-bounds write vulnerability in the VMware ESX VMXNET3 virtual network adapter that can enable guest-to-host code execution. The remediation guidance is to apply vendor patches and update affected VMware products to fixed versions.
Broadcom said CVE-2026-47876 was privately reported by Nguyen Hoang Thach of STARLabs SG through the Pwn2Own competition operated by Trend Micro's Zero Day Initiative. The references do not provide a specific date for the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.