VMware Fusion Flaw Could Allow Attackers to Gain Root Privileges
ID: 91338499-eef1-582b-ba20-b0fb1e16d1b1
STIX ID: report--91338499-eef1-582b-ba20-b0fb1e16d1b1
Feed Name: GBHackers
Threat Score
A high-severity local privilege escalation vulnerability (CVE-2026-41702, CVSS 7.8) was disclosed in VMware Fusion (25H2) involving a TOCTOU race condition in a setuid binary that can allow non-administrative local users to gain root; Broadcom released a fix in Fusion 26H1, no workarounds exist, and no public active exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
