CVE-2026-47876
CRITICALVmware Cloud Foundation < 9.1.x.x - Out-of-Bounds Access
Title source: ruleDescription
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
References (1)
Core 1
Scores
CVSS v3
9.3
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (10)
VMware/Cloud Foundation
5.x
VMware/Cloud Foundation
9.0.x.x
VMware/Cloud Foundation
9.1.x.x
VMware/ESX
8.0 - ESXi80U3k-25595708
VMware/ESX
9.0.x.x - ESXi-9.0.2.0100-25595025
VMware/ESX
9.1.x.x - ESXi-9.1.0.0200-25557999
VMware/Telco Cloud Platform
5.0.x
VMware/Telco Cloud Platform
5.1.x
VMware/vSphere Foundation
9.0.x.x
VMware/vSphere Foundation
9.1.x.x
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026