Broadcom has moved to patch a critical virtual machine escape vulnerability in VMware ESXi that could allow attackers to run code directly on the physical host from a compromised guest system. The flaw, tracked as CVE-2026-47876 and carrying a CVSS score of 9.3, undermines the fundamental isolation that secures virtualized environments.

The urgent update is part of a broader security release addressing five vulnerabilities across VMware products, including vCenter Server, Workstation, and Fusion. Three of the flaws are rated critical. Beyond the primary escape bug, two other critical vulnerabilities (CVE-2026-47877 and CVE-2026-47878) could also lead to host compromise, with one scenario requiring no administrative privileges inside the guest.

A successful exploit would grant an attacker control over the physical hypervisor. From that position, they could access data across all virtual machines on the host, deploy ransomware, or pivot deeper into the corporate network. The risk is amplified in cloud and multi-tenant settings, where a single host may serve numerous organizations.

Administrators are urged to prioritize patching. Fixed versions are now available, including ESXi and vCenter 8.0 Update 3g, ESXi and vCenter 7.0 Update 3n, alongside corresponding updates for Workstation and Fusion. Organizations must consult Broadcom's advisory for exact build numbers and apply the fixes immediately, prioritizing hosts with critical workloads or untrusted guests.

The incident highlights the perennial risk posed by hypervisors. A compromise at this layer bypasses the security architecture protecting hundreds of virtual machines. Regular patching of the virtualization stack is essential, complemented by strict network segmentation, least-privilege access, and vigilant monitoring for host-level anomalies.

For Hong Kong's technology sector, where VMware platforms underpin financial services, data centers, and enterprise infrastructure, this disclosure is a critical prompt to audit inventories and verify patch status. While no region-specific attacks have been reported for these CVEs, the global reach of the affected products means local operators face identical risks.

Security teams should also scrutinize environments hosting low-trust virtual machines, such as development sandboxes or customer-facing applications. Tightening guest configurations and limiting internal privileges provide vital defense-in-depth alongside the vendor patches.

The coordinated release underscores the importance of swift vendor action when core infrastructure is at risk. It also serves as a reminder for organizations using mixed environments to maintain rigorous, layered security controls, regardless of the underlying platform.

Any organization that has not yet begun remediation should immediately identify all instances of the affected software, map business-critical workloads to those hosts, and schedule emergency maintenance windows. Leaving this vulnerability unaddressed creates a clear pathway for full host takeover—a risk no modern enterprise can afford.


博通已著手修補 VMware ESXi 中一個嚴重的虛擬機逃逸漏洞,該漏洞可能讓攻擊者從受入侵的虛擬機直接在實體主機上執行代碼。此漏洞被編錄為 CVE-2026-47876,CVSS 評分為 9.3,動搖了保障虛擬化環境安全的基本隔離機制。

這項緊急更新是更廣泛安全發佈的一部分,旨在解決包括 vCenter Server、Workstation 和 Fusion 在內的 VMware 產品中的五個漏洞。其中三個漏洞被評定為嚴重級別。除了主要的逃逸漏洞外,另外兩個嚴重漏洞(CVE-2026-47877 和 CVE-2026-47878)也可能導致主機被入侵,其中一種情況甚至無需虛擬機內的管理權限。

成功的漏洞利用將使攻擊者控制實體虛擬機管理程式。由此,他們可以存取主機上所有虛擬機的數據、部署勒索軟件,或進一步滲入企業網絡。在雲端和多租戶環境中,風險會被放大,因為單一主機可能為眾多機構提供服務。

管理員被敦促優先處理補丁。現已提供修復版本,包括 ESXi 和 vCenter 8.0 Update 3g、ESXi 和 vCenter 7.0 Update 3n,以及對應的 Workstation 和 Fusion 更新。機構必須查閱博通的安全公告以獲取確切的組建編號,並立即套用修補程式,優先處理運行關鍵工作負載或不受信任虛擬機的主機。

此事件突顯了虛擬機管理程式始終存在的風險。此層級的入侵可繞過保護數百台虛擬機的安全架構。定期更新虛擬化堆棧至關重要,輔以嚴格的網絡分段、最小權限訪問原則,以及對主機級異常的警惕監控。

對香港的科技界而言,VMware 平台支撐著金融服務、數據中心和企業基礎設施,此次披露是審核資產清單和驗證補丁狀態的關鍵提示。雖然這些 CVE 尚未有針對特定地區的攻擊報告,但受影響產品的全球影響力意味著本地營運商面臨相同的風險。

安全團隊亦應審查託管低信任度虛擬機的環境,例如開發測試沙箱或面向客戶的應用程式。在供應商補丁之外,強化虛擬機配置和限制內部權限,提供了重要的縱深防禦。

這次協調發佈強調了當核心基礎設施面臨風險時,供應商迅速行動的重要性。它亦提醒使用混合環境的機構,無論底層平台如何,都必須維持嚴謹、多層次的安全控制。

任何尚未開始補救措施的機構,應立即識別受影響軟件的所有實例,將業務關鍵工作負載對應到這些主機,並安排緊急維護窗口。置此漏洞於不顧,將為完全主機接管創造明確途徑——這是任何現代企業都無法承擔的風險。

新聞來源 / Original News Source