logo

VMware Fusion Flaw Could Allow Attackers to Gain Root Privileges

ID: 91338499-eef1-582b-ba20-b0fb1e16d1b1

STIX ID: report--91338499-eef1-582b-ba20-b0fb1e16d1b1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Divya

...
...

A high-severity local privilege escalation vulnerability (CVE-2026-41702, CVSS 7.8) was disclosed in VMware Fusion (25H2) involving a TOCTOU race condition in a setuid binary that can allow non-administrative local users to gain root; Broadcom released a fix in Fusion 26H1, no workarounds exist, and no public active exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.