Broadcom has released security updates addressing two vulnerabilities in VMware Workstation and Fusion. The most severe is CVE-2026-59346, an integer-overflow vulnerability with a CVSS score of 9.3. A local attacker with elevated privileges can exploit this flaw to execute arbitrary code on the host system. The vulnerability affects VM administrators, potentially allowing them to break out of the virtual machine and execute code on the underlying host. Broadcom's patches address both flaws, and users are urged to apply updates promptly given the critical severity rating.
Two vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1. CVE-2026-59346 (CVSS 9.3) is a critical integer-overflow vulnerability in the VMXNET3 virtual network adapter that allows a local attacker with administrative privileges inside a virtual machine to execute arbitrary code on the host system. CVE-2026-59347 (CVSS 8.1) is a stack-based buffer-overflow vulnerability in HGFS (Host-Guest File System) that allows a local admin on a VM to execute code as the VMX process running on the host. Both vulnerabilities require the attacker to already possess local administrative privileges within the virtual machine, which could be obtained through phishing or exploiting weak user configurations. No evidence of in-the-wild exploitation has been reported for these two CVEs. Related VMware vCenter vulnerabilities CVE-2026-59309 and CVE-2026-59310 were actively exploited, with the latter suspected to be weaponized by a China-nexus APT actor, breaching 361 unique victim IPs across 47 countries, with most infections in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
Update VMware Workstation to version 26H1u1 and VMware Fusion to version 26H1u1, which contain patches for both CVE-2026-59346 and CVE-2026-59347. No workarounds are available for either vulnerability. Restrict local administrative privileges within virtual machines to trusted users only. Monitor for phishing attempts and weak user configurations that could be used to gain the required elevated privileges for exploitation.