VMware fixes two serious Workstation and Fusion flaws

Broadcom issued updates fixing an integer overflow (CVE-2026-59346) and a stack-based buffer overflow (CVE-2026-59347) in VMware Workstation and Fusion 26H1u1.

Broadcom released security updates Thursday that resolve two vulnerabilities in VMware Workstation and VMware Fusion. The fixes are included in update 26H1u1 and address flaws present in versions 25H2 and 26H1.

The first defect, tracked as CVE-2026-59346 and carrying a CVSS score of 9.3, is an integer overflow. Broadcom’s advisory explains that a malicious actor with local administrative privileges on a virtual machine using the VMXNET3 virtual network adapter may exploit the flaw to execute code on the host.

The second issue, CVE-2026-59347, is a stack-based buffer overflow with a CVSS score of 8.1. According to Broadcom, an attacker with local administrative access inside a virtual machine could exploit the bug to run code as the virtual machine’s VMX process on the host.

Broadcom reports both issues were disclosed privately and states there are no known workarounds. The company recommends installing update 26H1u1 as soon as practical. Broadcom also notes it has not observed these specific vulnerabilities being exploited in the wild.

The vulnerabilities enable a path from a guest virtual machine to the host system when an attacker already holds administrative privileges inside the VM. VMXNET3 is a paravirtualized network adapter used to improve guest network performance; defects tied to that component can be used to break VM isolation.

The advisory lists no mitigations other than applying the patched release. Security teams may review installed versions of Workstation and Fusion, deploy 26H1u1 where required, and follow any further vendor guidance. More than two dozen VMware vulnerabilities are currently tracked on the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities list.

Articles by this author