Critical

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Security Affairs

Overview

Broadcom has addressed a serious vulnerability in VMware ESXi that could allow attackers to execute code on a host machine from a compromised virtual machine. This flaw, identified as CVE-2026-47876, has a high severity rating of 9.3 on the CVSS scale, indicating a significant risk. Alongside this critical issue, Broadcom released patches for four other vulnerabilities affecting VMware's ESXi, vCenter, Workstation, and Fusion products, three of which are also classified as critical. Companies using these systems should prioritize applying the patches to safeguard their environments, as the potential for exploitation could lead to severe data breaches or system compromises.

Key Takeaways

  • Affected Systems: VMware ESXi, vCenter, Workstation, Fusion
  • Action Required: Broadcom has released patches to mitigate the vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a […]

Impact

VMware ESXi, vCenter, Workstation, Fusion

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

Broadcom has released patches to mitigate the vulnerabilities. Specific patch numbers or versions were not mentioned, but users should ensure they are on the latest versions of VMware products to receive these updates.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, VMware, Vulnerability, and 1 more.

Related Coverage

CISA warns of Chinese "BrickStorm" malware attacks on VMware servers

BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a new malware threat named BrickStorm, which is being used by Chinese hackers to backdoor VMware vSphere servers. This poses a significant risk to organizations using these servers, as it could lead to unauthorized access and potential data breaches.

Dec 4, 2025

VMware ESXi zero-days likely exploited a year before disclosure

BleepingComputer

Cybersecurity researchers have uncovered that a group of Chinese-speaking hackers exploited vulnerabilities in VMware ESXi, using a compromised SonicWall VPN appliance to deploy an exploit toolkit. This toolkit appears to have been created over a year before the vulnerabilities were publicly disclosed. This means that the attackers had access to these exploits long before companies were aware of their existence, potentially allowing them to infiltrate networks unnoticed. Organizations using VMware ESXi should be particularly vigilant, as the vulnerabilities could lead to significant security breaches. The incident underscores the need for companies to regularly update their systems and monitor for unusual activity, as these types of attacks can have serious implications for data security.

Jan 8, 2026

2024 VMware Flaw Now in Attackers’ Crosshairs

SecurityWeek

A newly discovered vulnerability in VMware products allows attackers to execute remote code by sending specially crafted network packets. This critical-severity flaw poses a serious risk for organizations using affected VMware systems, as it could lead to unauthorized access and control over their networks. VMware has not specified which products are impacted, but the nature of the vulnerability suggests that any systems relying on VMware technologies could be at risk. Companies should prioritize patching their systems as soon as updates are available to prevent potential exploitation. The urgency is heightened as this vulnerability is now a target for attackers.

Jan 26, 2026

CISA: VMware ESXi flaw now exploited in ransomware attacks

BleepingComputer

CISA has reported that ransomware gangs are now exploiting a serious vulnerability in VMware ESXi, which allows attackers to escape sandboxes and gain unauthorized access to systems. This vulnerability, which had previously been used in zero-day attacks, poses a significant risk to organizations using affected VMware products. Companies relying on VMware ESXi for virtualization need to be particularly vigilant, as attackers are actively targeting this flaw. The exploitation of such vulnerabilities can lead to severe data breaches and financial losses. Organizations should prioritize patching their systems to mitigate this risk and protect sensitive data from potential ransomware attacks.

Feb 4, 2026

7 Severe Vulnerabilities Patched in VMware Avi Load Balancer

SecurityWeek

VMware has patched seven serious vulnerabilities in its Avi Load Balancer that could allow attackers to bypass authentication, execute remote code, escalate privileges, and traverse directories. These vulnerabilities pose a significant risk to organizations relying on this load balancing technology, as they could lead to unauthorized access and control over systems. Users of VMware Avi Load Balancer should prioritize applying the latest patches to safeguard their environments. The severity of these vulnerabilities highlights the ongoing need for vigilance in cybersecurity practices, especially for widely used infrastructure components.

Jul 14, 2026

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

The Hacker News

Mozilla has rolled out updates for Firefox to fix two serious vulnerabilities that could be exploited by attackers. The flaws, identified as CVE-2026-15718 and CVE-2026-15719, involve issues with JavaScript: WebAssembly and site isolation in the DOM: Navigation component. Mozilla has warned users that exploit code for these vulnerabilities is already available publicly, increasing the urgency for users to update. It’s crucial for Firefox users to install these updates promptly to protect against potential attacks that could compromise their security and privacy. Keeping software up to date is a key defense against such risks.

Jul 15, 2026