Critical VM Escape Vulnerability Patched in VMware ESXi
PatchESXivCenterOur summary
Broadcom has issued a security update addressing multiple vulnerabilities in VMware products, including a critical VM escape flaw tracked as CVE-2026-47876. This vulnerability affects the VMXNET3 virtual network adapter in ESXi and could allow an attacker with local admin access to run arbitrary code on the host system. Other critical issues include a vCenter authentication bypass (CVE-2026-59309) and remote code execution (CVE-2026-59310). Broadcom says no active exploitation has been observed yet, but urges users to apply the latest patches promptly.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.