Executive brief
VMware ESX is a virtualization platform used to run multiple virtual servers on a single physical machine. A vulnerability in the VMXNET3 virtual network adapter allows a user with administrative control over a single virtual machine to break out of that environment and execute commands on the underlying host server. This could lead to a total compromise of all other virtual machines running on the same physical hardware.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the VMXNET3 virtual network adapter component of VMware ESX. A malicious actor with local administrative privileges on a guest virtual machine can exploit this flaw to escape the virtualized environment and execute arbitrary code on the ESXi host. The vulnerability is specific to the VMXNET3 adapter; other virtual network adapter types are not affected. This issue was reported via Pwn2Own and is addressed in various ESXi 8.0 and 9.x patch releases.
Affected products
- VMware ESX / ESXi 8.0 before ESXi80U3k-25595708, 9.0.x.x before ESXi-9.0.2.0100-25595025, 9.1.x.x before ESXi-9.1.0.0200-25557999
- VMware Cloud Foundation 5.x, 9.0.x.x, 9.1.x.x
- VMware vSphere Foundation 9.0.x.x, 9.1.x.x
- VMware Telco Cloud Platform 5.0.x, 5.1.x
Timeline
- 2026-07-29: advisory: Initial publication by Broadcom (VMSA-2026-0006)
- 2026-07-30: disclosed: NVD publication date