Critical VM escape bug patched in VMware ESXi
Broadcom and VMware issued patches for a critical ESXi VM escape flaw (CVE-2026-47876), two critical vCenter vulnerabilities, and fixes for Workstation and Fusion.
Broadcom on Wednesday published an advisory saying patches are available for vulnerabilities affecting VMware ESXi, vCenter, Workstation and Fusion. Three of the flaws have been assigned a critical severity rating.
The most severe issue is CVE-2026-47876, an out-of-bounds write in the VMXNET3 virtual network adapter used by ESXi. VMware described that a user with local administrator rights inside a virtual machine using VMXNET3 could exploit the bug to run arbitrary code on the host, a condition known as a VM escape.
Two critical vCenter vulnerabilities were patched in the same update. CVE-2026-59309 is an authentication bypass that can allow unauthorized access to vCenter. CVE-2026-59310 can enable an attacker with network access to execute arbitrary code on a vCenter server.
Broadcom’s advisory also lists a high-severity flaw, CVE-2026-41703, affecting ESXi, Workstation and Fusion. An account with VM deployment permissions could use that issue to obtain sensitive information or cause a denial-of-service in the host process. A separate low-severity ESXi issue, CVE-2026-41709, can allow certain administrator actions to proceed without being recorded in logs.
Broadcom said it is not aware of active exploitation of these vulnerabilities. The vendor urged organizations to apply the available updates and published an FAQ that explains the impact of each flaw and recommended mitigation steps.
Patches, technical details and update notes are available from Broadcom and VMware. The advisory materials include guidance to help organizations assess exposure, test fixes and schedule deployment.








