Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host
ID: 2606784b-a82a-5a21-a77f-6837ead89e8e
STIX ID: report--2606784b-a82a-5a21-a77f-6837ead89e8e
Feed Name: cybersecurityNews.com
Threat Score
Broadcom published VMSA-2026-0007 describing two VMware Workstation/Fusion flaws—CVE-2026-59346 (VMXNET3 integer overflow, CVSS 9.3) and CVE-2026-59347 (HGFS stack buffer overflow, CVSS 8.1)—that allow an attacker with local administrative access inside a guest VM to execute code on the host; Broadcom released patch 26H1u1 to remediate both issues and states no workarounds exist, so administrators should apply the update promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
