Critical vulnerability in VMware Workstation and Fusion updates

Critical vulnerability in VMware Workstation and Fusion updates

Broadcom on Thursday announced patches for two critical and high-level vulnerabilities in VMware Workstation and Fusion.

The first edition, tracked as CVE-2026-59346 (CVSS score of 9.3) is described as an integer overflow error that results in arbitrary code execution.

“A malicious actor with local administrative privileges on a virtual machine with the VMXNET3 virtual network adapter can exploit this issue to execute code on the host,” Broadcom states in its report advisory.

Tracked as CVE-2026-59347 (CVSS score of 8.1), the second flaw is a stack-based buffer overflow, which could lead to similar results although the exploitation conditions are different.

“A malicious actor with local administrative privileges on a virtual machine can exploit this issue to execute code while the virtual machine’s VMX process is running on the host,” Broadcom explains.

Both vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1 and have been fixed in version 26H1u1.

Advertising. Scroll to continue reading.

There are no workarounds for either vulnerability and Broadcom recommends updating to a patched iteration as soon as possible.

The company makes no mention of any of these vulnerabilities being exploited in the wild, saying both issues were privately reported to it.

However, security flaws in VMware products are often exploited by threat actors. There are currently more than two dozen VMware vulnerabilities included in CISAs KEV list.

Related: CISA calls for immediate patching of exploited Microsoft, VMware and Apple vulnerabilities

Related: Exploit for Fresh Cleo Harmony vulnerability released

Related: SonicWall warns of two SMA1000 zero-days being exploited in attacks

Related: Hackers begin exploiting critical Langflow vulnerability

Leave a Reply

Your email address will not be published. Required fields are marked *