CVE-2026-47876 – VMware Cloud Foundation

CVSS 9.3 CRITICAL Critical - Same Day Deployment

“One unpatched virtualization platform can expose every workload it protects.”

This patch addresses multiple vulnerabilities affecting VMware Cloud Foundation components. CVE-2026-59309 has a CVSS score of 9.8, Critical severity, and allows an attacker with network access to vCenter to bypass authentication through the VMware Directory Service and gain unauthorized access. CVE-2026-47876 has a CVSS score of 9.3, Critical severity, and affects the VMXNET3 virtual network adapter in VMware ESX, allowing code execution on the host from a virtual machine with local administrative privileges. CVE-2026-41703 has a CVSS score of 7.6, High severity, and affects VMware ESX, Workstation, and Fusion through an out-of-bounds read that can result in information disclosure or, more commonly, a denial-of-service condition. CVE-2026-41709 has a CVSS score of 2.7, Low severity, and allows certain administrator actions to occur without sufficient logging.

The update resolves vulnerabilities that impact authentication, memory handling, and audit logging across VMware environments. While no verified real-world exploitation has been reported for these vulnerabilities, the presence of two Critical vulnerabilities—including an authentication bypass and a host code execution flaw—makes this a high-priority update. The host code execution vulnerability exhibits Remote Code Execution (RCE) and Elevation of Privilege (EoP) characteristics, while the out-of-bounds read vulnerability has RCE characteristics based on the supplied assessment.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-787
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.