Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code
Key Takeaways Broadcom has disclosed two critical vulnerabilities affecting VMware Workstation and Fusion. The flaws, CVE-2026-59346 and CVE-2026-59347, could allow attackers to escape a virtual...
Key Takeaways
- Broadcom has disclosed two critical vulnerabilities affecting VMware Workstation and Fusion.
- The flaws, CVE-2026-59346 and CVE-2026-59347, could allow attackers to escape a virtual machine and execute code on the host system.
- Affected versions include VMware Workstation 25H2 and 26H1, and VMware Fusion 25H2 and 26H1.
- A patch, version 26H1u1, is available, and no workarounds exist for these vulnerabilities.
Critical Flaws Threaten VMware Workstation and Fusion Environments
Broadcom has issued an urgent security advisory, revealing two significant vulnerabilities within VMware Workstation and Fusion that could allow malicious actors to break out of a virtual machine (VM) and execute arbitrary code on the underlying host system. This scenario directly compromises the fundamental security principle of virtualization, which relies on isolating guest environments from the host.
Table Of Content
Details of the Vulnerabilities
The advisory, designated VMSA-2026-0007 and published on September 3, 2026, outlines two distinct security weaknesses impacting VMware’s widely adopted desktop virtualization solutions. The more severe of the pair, identified as CVE-2026-59346, is an integer-overflow vulnerability residing within the VMXNET3 virtual network adapter. Broadcom has assigned this flaw a CVSSv3 score of 9.3, classifying it as critical.
According to the advisory, an attacker who has already obtained local administrative privileges within a virtual machine configured with a VMXNET3 adapter could leverage this flaw. Successful exploitation would enable them to execute code directly on the host machine, effectively bypassing the intended isolation of the VM sandbox.
The second vulnerability, CVE-2026-59347, is a stack-based buffer-overflow issue found in the Host-Guest File System (HGFS), a component responsible for managing shared folders between a VM and its host.
This particular flaw carries a CVSSv3 score of 8.1, placing it in the “important” severity category. Exploiting CVE-2026-59347 would allow an attacker with administrative access inside a guest VM to execute code as the VMX process on the host. This provides a critical foothold in host-level operations without needing to directly exploit the network adapter.
Discovery and Attribution
Both vulnerabilities were privately reported to Broadcom, indicating they were not discovered through public exploitation. Broadcom has acknowledged and credited several independent research teams for their contributions to these findings.
Specifically, CVE-2026-59346 was reported independently by h4urek of secsys lab, as well as by Y² and Stan S, who submitted their findings through Trend Micro’s Zero Day Initiative. CVE-2026-59347 was reported by Yeonghyeon Choi and Tianchu Chen from Tencent’s Xuanwu Lab.
Affected Products and Remediation
The vulnerabilities impact VMware Workstation versions 25H2 and 26H1, regardless of the host operating system. Similarly, VMware Fusion versions 25H2 and 26H1 running on macOS are also affected. Broadcom has released version 26H1u1 to address both flaws across the entire affected product range. Crucially, the advisory states that no workarounds are available for either vulnerability. This means that relying on configuration changes alone will not mitigate the risk; applying the official patch is the sole method for protection.
Given that both flaws only require local administrative privileges within a guest VM to achieve host-level compromise, security teams utilizing VMware Workstation or Fusion in environments such as labs, testing facilities, or for malware analysis should prioritize this patch. Virtualization platforms are frequently employed to isolate potentially untrusted code, and an active VM-escape vulnerability could enable attackers to pivot directly from a contained sandbox into production infrastructure.
What You Should Do
- Immediately update VMware Workstation and Fusion to version 26H1u1 to remediate both CVE-2026-59346 and CVE-2026-59347.
- Audit all virtual machines to identify those configured with VMXNET3 adapters or utilizing shared folder features, as these components are central to the vulnerabilities.
- Prioritize patching in environments where untrusted code is processed or where isolation is critical, such as security research labs or testing environments.
- Regularly monitor Broadcom’s security advisories for further updates and recommendations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.