Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution
Overview
Broadcom has addressed a serious vulnerability in VMware ESXi that could allow attackers to execute code on a host machine from a compromised virtual machine. This flaw, identified as CVE-2026-47876, has a high severity rating of 9.3 on the CVSS scale, indicating a significant risk. Alongside this critical issue, Broadcom released patches for four other vulnerabilities affecting VMware's ESXi, vCenter, Workstation, and Fusion products, three of which are also classified as critical. Companies using these systems should prioritize applying the patches to safeguard their environments, as the potential for exploitation could lead to severe data breaches or system compromises.
Key Takeaways
- Affected Systems: VMware ESXi, vCenter, Workstation, Fusion
- Action Required: Broadcom has released patches to mitigate the vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a […]
Impact
VMware ESXi, vCenter, Workstation, Fusion
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Broadcom has released patches to mitigate the vulnerabilities. Specific patch numbers or versions were not mentioned, but users should ensure they are on the latest versions of VMware products to receive these updates.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, VMware, Vulnerability, and 1 more.