CVE-2026-20794Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (high) impacts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-12); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 105-1205-1305-14
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-131
Disclosure1
2026-05-141
Patch1
Full discourse3 posts
  • Ori Nimron@orinimron123
    Disclosure

    1/n: Yesterday was a good day, got credited for 7 CVEs: 3 Intel datacenter GPU vulnerabilities which allowed ESXi VM sandbox escape: - CVE-2026-20794 - CVE-2026-20879 - CVE-2026-20751 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01402.html https://t.co/4if3Fei2pm

    Post summary

    The user reports being credited for seven CVEs, including three Intel datacenter GPU weaknesses that enable ESXi VM sandbox escapes, and references Intel’s security advisory for further details.

    2202031.4K
    488 followersView on X
  • Elusive@ElusivePrivacy
    Patch

    Intel and AMD publish 24 advisories covering 70 vulns. Intel's worst: CVE-2026-20794 (CVSS 9.3) buffer overflow in Data Center Graphics Driver for VMware ESXi, privilege escalation + potential RCE. Also patches for UEFI firmware, EMA, and QAT drivers. Source: SecurityWeek Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Intel and AMD issued advisories for CVE-2026-20794, detailing a buffer overflow that allows privilege escalation and potential RCE, while providing patches for affected drivers and firmware.

    0101080
    172 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Intel Data Center Graphics Driver for VMware ESXi Buffer Overflow (CVE-2026-20794) A buffer overflow in the Intel Data Center Graphics Driver for VMware ESXi (before version 2.0.2) may allow a privileged local attacker to escalate privileges and execute arbitrary code. The vulnerability has high impact on confidentiality, integrity, and availability. 👉Affected: Intel Data Center Graphics Driver for VMware ESXi < 2.0.2

    Post summary

    The message discloses a buffer overflow vulnerability (CVE-2026-20794) in Intel Data Center Graphics Driver for VMware ESXi, noting its potential for privilege escalation and code execution.

    0002082
    187 followersView on X

Explore more