Impact of CVE-2026-46243 on VMware ESXi
search cancel

Impact of CVE-2026-46243 on VMware ESXi

book

Article ID: 446729

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

CVE-2026-46243 (also known as CIFSwitch) is a Linux kernel privilege escalation flaw discovered in 2026. An unprivileged local user can exploit this vulnerability to get a full root shell. The flaw exists because the kernel's CIFS client incorrectly validates user-provided inputs within cifs.spnego descriptions. For more details on this, refer to following article -CVE-2026-46243

Environment

VMware vSphere ESXi

Resolution

 By default, ESXi does not install the cifs-utils package mentioned. Since this critical software component is missing from the environment, the platform( VMware ESXi) is not directly exposed or impacted by this CVE-2026-46243.