
CVE-2026-47876: VMware ESXi — VM Escape Enables Host Compromise (June 2026)
CVE-2026-47876 — VMware ESXi
CVE-2026-47876 is a critical vulnerability in VMware ESXi that allows a local administrator on a guest VM to escape the virtual machine boundary and execute arbitrary code on the ESXi host. This flaw, rated critical, is not confirmed as actively exploited but poses immediate risk of full hypervisor compromise. Additional critical vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-41703, CVE-2026-41709) were also patched, including vCenter authentication bypass and arbitrary code execution.
Attack Vector
Attackers require administrative privileges on a guest VM to exploit CVE-2026-47876. By leveraging this access, they can execute crafted code that breaks out of the VM sandbox and runs on the underlying ESXi host. The related vulnerabilities allow attackers with network or limited access to bypass authentication controls, execute code, or cause denial of service. No public indicators of compromise (IOCs) have been released, but exploitation would likely result in anomalous host-level processes initiated from guest VM contexts.
Who Is at Risk
All organizations running affected versions of VMware ESXi and vCenter are at risk, especially those with multi-tenant or untrusted VM workloads. VMware is the confirmed affected vendor. Environments exposing management interfaces or allowing users administrative VM access are at highest risk of exploitation and lateral movement.
Patch & Mitigate
- Patch: Apply the latest VMware ESXi and vCenter security updates released June 2026. Refer to VMware advisories for exact build numbers and hotfixes.
- Workaround: No viable workaround is available. Restrict administrative access to VMs and management interfaces as a temporary measure.
- Detect: Monitor for unexpected host-level process creation originating from guest VMs, failed authentication attempts, and anomalous activity in ESXi or vCenter logs.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers require initial admin access to a VM to launch the exploit.
- TA0005 — Defense Evasion: VM escape enables bypass of hypervisor isolation controls.
- TA0006 — Credential Access: Related authentication bypass flaws could allow attackers to escalate privileges or move laterally.
Source: https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

