VMXNET3 Escape Expands VMware Patch Blast Radius

A VMware patch is more than a guest bug fix when it touches the host and the control plane. One flaw lets a local VM admin break out into ESXi, and two critical vCenter bugs hit the management layer that controls the fleet, so compromise can move upward instead of stopping at a single virtual machine. Broadcom says it patched five flaws across ESXi, vCenter, Workstation, and Fusion. The critical issues are CVE-2026-47876, an out-of-bounds write in VMXNET3 that VMware describes as a VM escape, CVE-2026-59309, a vCenter authentication bypass, and CVE-2026-59310, a vCenter flaw that can allow code execution with network access. The practical risk is that patching one system is not enough if the attacker already reached vCenter or got admin inside a VM that uses VMXNET3. Guest isolation and management-plane trust are both in play here.

Sources