In a nutshell: The VMware vulnerability CVE-2026-47876 allows attackers to escape from virtual machines on ESX and vCenter systems and requires rapid patching.
VMware by Broadcom published security advisory VMSA-2026-0006 on 29 July 2026, which documents a vulnerability (CVE-2026-47876) that enables escape from virtual machines on ESX, vCenter and Workstation systems.
The vulnerability CVE-2026-47876 reported by vendor VMware by Broadcom affects multiple products in the VMware family, notably including ESX instances, vCenter and Workstation. The risk lies in the fact that an attacker operating from within a virtual machine can breach VM boundaries and gain access to the host system or neighbouring virtual machines (VM escape).
ESX administrators are primarily affected. A successful exploit would equip an attacker with access to the host infrastructure and thus potentially endanger all VMs in the affected cluster. This is particularly true for environments where multiple tenants or critical workloads run on the same host.
VMware by Broadcom released the official advisory VMSA-2026-0006 on 29 July 2026. Affected organisations should immediately verify which versions of their ESX, vCenter and Workstation systems are in use and apply available security patches. Priority should be given to production ESX environments.
Source: borncity.com · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.