Back to Feed
VulnerabilitiesSep 4, 2026

VMware Workstation and Fusion Updates Patch Critical Vulnerability

VMware Workstation and Fusion patched critical vulnerabilities allowing host code execution.

Summary

Broadcom has released patches for two critical vulnerabilities in VMware Workstation and Fusion. CVE-2026-59346, an integer overflow, and CVE-2026-59347, a stack-based buffer overflow, could allow attackers with local administrative privileges within a virtual machine to execute code on the host system. While no exploitation in the wild has been reported, VMware products are frequently targeted.

Full text

Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as CVE-2026-59346 (CVSS score of 9.3), is described as an integer overflow bug leading to arbitrary code execution. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” Broadcom notes in its advisory. Tracked as CVE-2026-59347 (CVSS score of 8.1), the second flaw is a stack-based buffer overflow that could lead to similar outcomes, albeit the exploitation conditions are different. “A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host,” Broadcom explains. Both vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1 and were resolved in version 26H1u1.Advertisement. Scroll to continue reading. There are no workarounds for either of the flaws, and Broadcom recommends updating to a patched iteration as soon as possible. The company makes no mention of any of these vulnerabilities being exploited in the wild, and says that both issues were reported to it privately. However, security defects in VMware products are often exploited by threat actors. More than two dozen VMware vulnerabilities are currently included in CISA’s KEV list. Related: CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Related: Exploit Published for Fresh Cleo Harmony Vulnerability Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Related: Hackers Start Exploiting Critical Langflow Vulnerability Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesExploit Published for Fresh Cleo Harmony VulnerabilityMalicious Virtualizor Update Served via BGP HijackingChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedHackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data Breach Latest News Catch Raises $5 Million for AI Executive Assistant With GuardrailsGoogle Patches 6th Chrome Zero-Day of 2026Manchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsHiddenLayer Raises $100 Million for AI Runtime SecurityAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million153 Million Driver License Images Offered on Dark WebOver 3 Million WordPress Sites Affected by Migration Plugin Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTom Bonos has been named Chief Revenue Officer at Sumo Logic.Axonius has appointed Chris Jones as CTSO and Dan Schoenbaum as SVP of Business Development.Optiv has appointed Sean Forkan as Chief Revenue Officer (CRO).More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-59346
  • cve — CVE-2026-59347

Entities

VMware Workstation (product)VMware Fusion (product)Broadcom (vendor)