VMware ESX 8.0 / 9.0 / 9.1 Out-of-Bounds Write (VMSA-2026-0006)

critical Nessus Plugin ID 337685

Synopsis

The VMware ESX host is affected by an out-of-bounds write vulnerability.

Description

The version of VMware ESX installed on the remote host is 8.0 prior to build 25595708 (8.0 Update 3k), or 9.0 prior to build 25595025 (9.0.2.0100), or 9.1 prior to build 25557999 (9.1.0.0200). It is, therefore, affected by a vulnerability as referenced in the VMSA-2026-0006.1 advisory:

- VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code as the virtual machine's VMX process running on the host. (CVE-2026-47876)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Apply the relevant patch referenced in the VMSA-2026-0006.1 advisory.

See Also

http://www.nessus.org/u?32b9f35d

Plugin Details

Severity: Critical

ID: 337685

File Name: vmware_esxi_vmsa-2026-0006_CVE-2026-47876.nasl

Version: 1.1

Type: Remote

Family: Misc.

Published: 8/18/2026

Updated: 8/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.02

CVSS v2

Risk Factor: High

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-47876

CVSS v3

Risk Factor: Critical

Base Score: 9.3

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:vmware:esxi

Required KB Items: Host/VMware/release, Host/VMware/version, Host/VMware/vsphere

Patch Publication Date: 7/29/2026

Vulnerability Publication Date: 7/29/2026

Reference Information

CVE: CVE-2026-47876

VMSA: 2026-0006