Back to Feed
VulnerabilitiesSep 5, 2026

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

VMware Workstation and Fusion have critical flaws allowing VM admins to execute host code.

Summary

Broadcom has released security updates for two critical vulnerabilities in VMware Workstation and Fusion. CVE-2026-59346, an integer overflow flaw, allows local attackers with elevated privileges to execute arbitrary code on the host. A separate stack-based buffer overflow in HGFS (CVE-2026-59347) also permits code execution as the VMX process. Both require prior administrative access within the VM.

Full text

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code Ravie LakshmananSep 05, 2026Vulnerability / Server Security Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host," Broadcom said in an alert. The tech giant credited @h4urek, @cameudis, and Stan S for discovering the issue. Also patched by Broadcom is a stack-based buffer-overflow vulnerability in HGFS (CVE-2026-59347, CVSS score: 8.1), which can be exploited by a bad actor with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab have been acknowledged for reporting the flaw. In both cases, successful exploitation hinges on an attacker already possessing local administrative privileges, although it's worth noting that they can be obtained through a separate compromise through phishing or exploiting weak user configurations. The two vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. Broadcom said there are no workarounds that address the two vulnerabilities, adding that they have been patched in VMware Workstation 26H1u1 and VMware Fusion 26H1u1. Although there is no evidence that the security flaws have been exploited in the wild, vulnerabilities in VMware products have been an attack magnet. As recently as last month, threat actors were observed actively exploiting two shortcomings in VMware vCenter, namely CVE-2026-59309 and CVE-2026-59310, with the latter suspected to be weaponized by a China-nexus advanced persistent threat (APT) actor. The activity, which started five calendar days after public disclosure of the flaw, is estimated to have breached 361 unique victim IP addresses across 47 countries. Most of the infections were concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25). Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Virtualization Security, VMware, Vulnerability ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Indicators of Compromise

  • cve — CVE-2026-59346
  • cve — CVE-2026-59347

Entities

VMware Workstation (product)VMware Fusion (product)Broadcom (vendor)