logo

Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host

ID: 2606784b-a82a-5a21-a77f-6837ead89e8e

STIX ID: report--2606784b-a82a-5a21-a77f-6837ead89e8e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-03

Date Updated: 2026-09-16

Author: Guru Baran

...
...

Broadcom published VMSA-2026-0007 describing two VMware Workstation/Fusion flaws—CVE-2026-59346 (VMXNET3 integer overflow, CVSS 9.3) and CVE-2026-59347 (HGFS stack buffer overflow, CVSS 8.1)—that allow an attacker with local administrative access inside a guest VM to execute code on the host; Broadcom released patch 26H1u1 to remediate both issues and states no workarounds exist, so administrators should apply the update promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.