Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code
September 3, 2026
Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware
September 3, 2026
StreamRAT Android Trojan Grants Full Remote Control via VNC, Accessibility
September 3, 2026
Home/CyberSecurity News/Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code
CyberSecurity News

Critical VMware Workstation and Fusion Flaws Let Attackers Execute Code

Key Takeaways Broadcom has disclosed two critical vulnerabilities affecting VMware Workstation and Fusion. The flaws, CVE-2026-59346 and CVE-2026-59347, could allow attackers to escape a virtual...

Sarah simpson
Sarah simpson
September 3, 2026 3 Min Read
2 0

Key Takeaways

  • Broadcom has disclosed two critical vulnerabilities affecting VMware Workstation and Fusion.
  • The flaws, CVE-2026-59346 and CVE-2026-59347, could allow attackers to escape a virtual machine and execute code on the host system.
  • Affected versions include VMware Workstation 25H2 and 26H1, and VMware Fusion 25H2 and 26H1.
  • A patch, version 26H1u1, is available, and no workarounds exist for these vulnerabilities.

Critical Flaws Threaten VMware Workstation and Fusion Environments

Broadcom has issued an urgent security advisory, revealing two significant vulnerabilities within VMware Workstation and Fusion that could allow malicious actors to break out of a virtual machine (VM) and execute arbitrary code on the underlying host system. This scenario directly compromises the fundamental security principle of virtualization, which relies on isolating guest environments from the host.

Table Of Content

  • Key Takeaways
  • Critical Flaws Threaten VMware Workstation and Fusion Environments
  • Details of the Vulnerabilities
  • Discovery and Attribution
  • Affected Products and Remediation
  • What You Should Do

Details of the Vulnerabilities

The advisory, designated VMSA-2026-0007 and published on September 3, 2026, outlines two distinct security weaknesses impacting VMware’s widely adopted desktop virtualization solutions. The more severe of the pair, identified as CVE-2026-59346, is an integer-overflow vulnerability residing within the VMXNET3 virtual network adapter. Broadcom has assigned this flaw a CVSSv3 score of 9.3, classifying it as critical.

According to the advisory, an attacker who has already obtained local administrative privileges within a virtual machine configured with a VMXNET3 adapter could leverage this flaw. Successful exploitation would enable them to execute code directly on the host machine, effectively bypassing the intended isolation of the VM sandbox.

The second vulnerability, CVE-2026-59347, is a stack-based buffer-overflow issue found in the Host-Guest File System (HGFS), a component responsible for managing shared folders between a VM and its host.

This particular flaw carries a CVSSv3 score of 8.1, placing it in the “important” severity category. Exploiting CVE-2026-59347 would allow an attacker with administrative access inside a guest VM to execute code as the VMX process on the host. This provides a critical foothold in host-level operations without needing to directly exploit the network adapter.

Discovery and Attribution

Both vulnerabilities were privately reported to Broadcom, indicating they were not discovered through public exploitation. Broadcom has acknowledged and credited several independent research teams for their contributions to these findings.

Specifically, CVE-2026-59346 was reported independently by h4urek of secsys lab, as well as by Y² and Stan S, who submitted their findings through Trend Micro’s Zero Day Initiative. CVE-2026-59347 was reported by Yeonghyeon Choi and Tianchu Chen from Tencent’s Xuanwu Lab.

Affected Products and Remediation

The vulnerabilities impact VMware Workstation versions 25H2 and 26H1, regardless of the host operating system. Similarly, VMware Fusion versions 25H2 and 26H1 running on macOS are also affected. Broadcom has released version 26H1u1 to address both flaws across the entire affected product range. Crucially, the advisory states that no workarounds are available for either vulnerability. This means that relying on configuration changes alone will not mitigate the risk; applying the official patch is the sole method for protection.

Given that both flaws only require local administrative privileges within a guest VM to achieve host-level compromise, security teams utilizing VMware Workstation or Fusion in environments such as labs, testing facilities, or for malware analysis should prioritize this patch. Virtualization platforms are frequently employed to isolate potentially untrusted code, and an active VM-escape vulnerability could enable attackers to pivot directly from a contained sandbox into production infrastructure.

What You Should Do

  • Immediately update VMware Workstation and Fusion to version 26H1u1 to remediate both CVE-2026-59346 and CVE-2026-59347.
  • Audit all virtual machines to identify those configured with VMXNET3 adapters or utilizing shared folder features, as these components are central to the vulnerabilities.
  • Prioritize patching in environments where untrusted code is processed or where isolation is critical, such as security research labs or testing environments.
  • Regularly monitor Broadcom’s security advisories for further updates and recommendations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitMalwarePatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Node.js Vulnerability CVE-2024-2798 Lets Attackers Deploy Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Sangoma Switchvox RCE Vulnerability Actively Exploited
September 3, 2026
Critical WordPress Plugin Flaw Exposes 5 Million Sites to SQL Injection
September 3, 2026
Critical Apache HTTP Server Vulnerability Lets Attackers Phish Users
September 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us