Broadcom just patched a VMware bug that lets a VM take over its host. it's not even the worst one

CVE-2026-47876 lets a VM break out and run code on the ESXi host underneath it. Broadcom patched five bugs at once — and the one graded lower is…

Aliteq
Priya Nair · Software & Systems Editor

The short version

Broadcom patched five VMware flaws at once: two rated 9.8 (vCenter), one rated 9.3 (ESXi/Workstation/Fusion VM escape), and two lower-severity issues.

The short version

CVE-2026-47876 is a VM escape in the VMXNET3 virtual network adapter — a VM with local admin can trigger memory corruption and run code on the ESXi host itself.

The short version

CVE-2026-59309 is an unauthenticated vCenter Directory Service auth bypass, scored 9.8 — higher than the escape, and it needs no privileges inside a VM at all.

The short version

Fixed in ESXi 9.1.0.0200 / 9.0.2.0100 / 8.0 Update 3k, vCenter 9.1.0.0300 / 9.0.2.0100 / 8.0 Update 3k, and Workstation/Fusion 26H1.

The short version

Broadcom says it has no evidence any of the five are being exploited in the wild yet — this is a patch-before-that-changes situation, not an active-breach one.

My take

I think the coverage calling this 'the VMware VM escape story' buried the lede. An unauthenticated path into vCenter is the one that lets someone walk in from the network with nothing — no…

Aliteq

Read the full story

Broadcom just patched a VMware bug that lets a VM take over its host. it's not even the worst one

Read the full story on Aliteq