Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has patched two VMware Workstation and Fusion vulnerabilities, including CVE-2026-59346, a critical integer-overflow flaw that could let a local attacker with elevated privileges execute code on the host. It also fixed CVE-2026-59347 in HGFS, while warning that VMware products remain a frequent target after recent exploitation of VMware vCenter flaws CVE-2026-59309 and CVE-2026-59310. #CVE-2026-59346 #CVE-2026-59347 #VMwareWorkstation #VMwareFusion #VMwarevCenter #CVE-2026-59309 #CVE-2026-59310

Keypoints

  • Broadcom released security updates for VMware Workstation and Fusion.
  • CVE-2026-59346 is a critical integer-overflow flaw with a CVSS score of 9.3.
  • Exploitation of CVE-2026-59346 could allow code execution on the host from a VM with VMXNET3.
  • CVE-2026-59347 is a stack-based buffer overflow in HGFS with a CVSS score of 8.1.
  • The flaws affect VMware Workstation and Fusion 25H2 and 26H1, with no workarounds available.

Read More: https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html