Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 Software Supply Chain Security Tools for 2026
October 8, 2026
Top 10 Secrets Detection Tools for 2026
October 8, 2026
Critical VMware VMXNET3 Flaw (CVE-2023-34051) Lets Attackers Execute Code
October 8, 2026
Home/CyberSecurity News/Critical VMware VMXNET3 Flaw (CVE-2023-34051) Lets Attackers Execute Code
CyberSecurity News

Critical VMware VMXNET3 Flaw (CVE-2023-34051) Lets Attackers Execute Code

Key Takeaways A critical integer overflow vulnerability, CVE-2026-59346, has been disclosed in VMware’s VMXNET3 virtual network adapter. The flaw could enable an attacker with administrative...

Jennifer sherman
Jennifer sherman
October 8, 2026 3 Min Read
3 0

Key Takeaways

  • A critical integer overflow vulnerability, CVE-2026-59346, has been disclosed in VMware’s VMXNET3 virtual network adapter.
  • The flaw could enable an attacker with administrative access within a guest virtual machine to execute code on the host system.
  • A public proof-of-concept (PoC) is now available, demonstrating a host process crash, though not full code execution.
  • Broadcom has patched the vulnerability in VMware Workstation and Fusion 26H1u1, released on September 3, 2026.

A significant security vulnerability affecting VMware’s VMXNET3 virtual network adapter has recently come to light with the release of a public proof-of-concept (PoC). Identified as CVE-2026-59346, this critical integer overflow flaw could potentially allow an attacker with administrative privileges inside a guest virtual machine to execute arbitrary code on the underlying host system.

Table Of Content

  • Key Takeaways
  • Vulnerability Details and Severity
  • Public PoC and Its Implications
  • What You Should Do

The PoC, developed and released by researcher 0xCyberstan, currently demonstrates a host process crash rather than full code execution. However, the potential for a more severe exploit remains a serious concern for virtualized environments.

Vulnerability Details and Severity

Broadcom, the vendor, has assigned a high severity score of 9.3 on the CVSSv3 scale to CVE-2026-59346. The vulnerability was addressed in VMware Workstation and Fusion version 26H1u1, which was made available on September 3, 2026. Affected versions include Workstation and Fusion 25H2 and 26H1. Broadcom’s security advisory explicitly states that no workaround is currently available for unpatched systems.

The core of the vulnerability lies within the TCP Segmentation Offload (TSO) processing path of the host’s VMware-VMX process. TSO is a networking technique designed to improve performance by allowing the operating system to pass large data packets to the network adapter, which then segments them into smaller, transmission-unit-sized packets. The flaw occurs during the memory allocation calculation for these segments.

Specifically, the vulnerable routine calculates the necessary memory by multiplying the number of segments by the required space per segment. This calculation uses a 32-bit multiplication. When the result of this multiplication exceeds the maximum value representable by 32 bits, an integer overflow occurs, causing the calculated value to “wrap around” to a significantly smaller number. Consequently, the host allocates a buffer that is much smaller than required.

Despite the undersized buffer, the copy loop proceeds using the original, larger segment count. This discrepancy leads to guest-controlled packet data being written beyond the boundaries of the allocated buffer, resulting in an out-of-bounds write condition.

The researcher noted a connection between this vulnerability and a previously patched code path for CVE-2025-41236. While earlier patches introduced checks to limit individual packet fields and their sum to 9,216, they did not validate the final multiplication result, leaving the door open for this new overflow scenario even with inputs below those prior limits.

Public PoC and Its Implications

The public PoC for CVE-2026-59346 is accessible via a GitHub repository. It operates as a Linux kernel module within a guest virtual machine configured with a VMXNET3 adapter. The PoC directly writes network transmit descriptors, bypassing the guest driver’s standard TSO handling, and then requests the host to process them. This operation requires elevated privileges within the guest OS and is not an unauthenticated remote network attack.

Executing the PoC triggers an out-of-bounds write that attempts to access unmapped memory, causing the vmware-vmx process to crash with a segmentation fault. This action effectively powers off the affected virtual machine. The 0xCyberstan repository warns that testing this PoC could lead to the loss of unsaved guest state. The researcher documented their testing environment using VMware Workstation Pro 25.0.1 on an Ubuntu host with an Alpine Linux guest.

The Zero Day Initiative (ZDI) advisory, published on September 9, corroborates that the underlying flaw has the potential to support arbitrary code execution within the hypervisor context. While ZDI assigned a CVSS score of 7.5, contrasting with Broadcom’s 9.3, both assessments confirm the severity. Crucially, the public PoC demonstrates memory corruption and a system crash, reinforcing the vulnerability’s existence and impact, even if it doesn’t yet achieve full guest-to-host code execution.

What You Should Do

  • Apply Patches Immediately: Administrators must install VMware Workstation and Fusion 26H1u1 or any later supported release as soon as possible.
  • Verify Host Versions: Do not assume that guest operating system updates will address this issue; the remedy lies in updating the host product.
  • Exercise Caution with PoCs: If testing the public PoC, do so only in isolated, authorized environments, as it is designed to crash the affected virtual machine process and could lead to data loss.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Best Software Composition Analysis (SCA) Tools for 2026

Next Post

Top 10 Secrets Detection Tools for 2026

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Top 10 API Security Tools for 2026
October 8, 2026
Splunk Patches Critical RCE Vulnerability CVE-2023-46214
October 8, 2026
Anthropic Claude Haiku 5.5 Offers Enhanced Coding and Computer Vision
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us