Published on September 3, 2026
[CVE-2026-59346, CVE-2026-59347] Critical VMware Workstation and Fusion Vulnerabilities Allow Code Execution on the Host
Severity
Critical
Detail
Broadcom has issued a security advisory, VMSA-2026-0007, addressing two vulnerabilities affecting VMware Workstation and VMware Fusion. The vulnerabilities could allow attackers to escape a guest virtual machine and execute code on the underlying host system, potentially compromising the security boundary provided by virtualization.
The most severe vulnerability, CVE-2026-59346, is an integer overflow vulnerability in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a guest VM configured with a VMXNET3 adapter could exploit the flaw to execute code on the host system.
The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow vulnerability in the Host-Guest File System (HGFS) component, which facilitates file sharing between guest VMs and host systems. An attacker with administrative privileges within a guest VM could exploit the flaw to execute code in the context of the VMX process on the host.
Successful exploitation of these vulnerabilities could enable attackers to escape the virtualized environment, gain access to host-level resources, and potentially pivot to other systems within the affected environment. Broadcom stated that there is currently no evidence of active exploitation; however, no workarounds are available, and immediate patching is strongly recommended.
| CVE ID | Summary | CVSS Score |
| CVE-2026-59346 | An integer overflow vulnerability in the VMXNET3 virtual network adapter could allow a malicious actor with administrative privileges in a guest VM to execute code on the host system. | 9.3 (Critical) |
| CVE-2026-59347 | A stack-based buffer overflow vulnerability in the HGFS could allow a malicious actor with administrative privileges in a guest VM to execute code in the context of the VMX process on the host. | 8.1 (High) |
Affected Products
The vulnerabilities affect the following VMware products:
- VMware Workstation 25H2 and 26H1 running on any supported host operating system.
- VMware Fusion 25H2 and 26H1 running on macOS.
Recommendation
Organizations should implement the following measures immediately to reduce the risk of exploitation:
- Upgrade VMware Workstation and VMware Fusion to version 26H1u1 or later.
- Prioritize patching systems used for malware analysis, software testing, development, and other environments that process untrusted code.
- Review virtualization hosts for suspicious activity originating from guest VMs.
- Restrict administrative access within guest virtual machines to trusted users only.
- Verify that all affected VMware Workstation and Fusion deployments have been updated, as no workarounds are available.
Source
https://cybersecuritynews.com/vmware-workstation-and-fusion-vulnerabilities/
