Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5005 articles · 188942 vulns · 37/41 feeds (7d)
← Back to list
9.3
CVE-2026-47876PATCHED
VMware · Cloud Foundation

VMXNET3 out-of-bounds write vulnerability

Description

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Affected Products

VendorProductVersions
VMwareCloud Foundation9.1.x.x, 9.0.x.x, 5.x, 9.1.x.x, 9.0.x.x, 9.1.x.x, 9.0.x.x, 8.0, 5.1.x, 5.0.x

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
vmwarevsphere foundationmitre_affected90%
vmwareesxmitre_affected90%
vmwaretelco cloudmitre_affected90%

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

Related News (5 articles)

Tier D
BleepingComputer13d ago
VMware fixes three critical flaws allowing auth bypass, VM escapes
→ No new info (linked only)
Tier B
CCCS Canada13d ago
VMware security advisory (AV26-763)
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-47876 | VMware ESX VMXNET3 virtual network adapter out-of-bounds write
→ No new info (linked only)
Tier D
Heise Security13d ago
VMware ESX, vCenter, Workstation und Fusion: Updates schließen kritische Lücken
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits VMware (30 juillet 2026)
→ No new info (linked only)
CVSS 3.19.3 CRITICAL
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
ESXi-9.1.0.0200-25557999ESXi-9.0.2.0100-25595025ESXi80U3k-25595708
CWECWE-787
PublishedJul 30, 2026
Last enriched13d ago
Trending Score14
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59310EXPKEV
vCenter directory-traversal vulnerability
Trending: 137
CRITICALCVE-2026-59309
vCenter authentication-bypass vulnerability
Trending: 17
HIGHCVE-2026-41703
Out-of-bounds read vulnerability
Trending: 14
HIGHCVE-2026-41842
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Trending: 13
HIGHCVE-2026-41850EXP
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Trending: 11

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Jul 30, 2026