Root Access Race: TOCTOU Vulnerability (CVE-2026-41702) Hits VMware Fusion
ID: 0345594d-fad8-5d32-a510-79351d4b8aa6
STIX ID: report--0345594d-fad8-5d32-a510-79351d4b8aa6
Feed Name: securityonline.info
Threat Score
Broadcom released patches for VMware Fusion addressing CVE-2026-41702, a TOCTOU (time-of-check/time-of-use) local privilege escalation in a SETUID binary affecting Fusion 25H2; a local attacker can potentially escalate to root. The issue is rated CVSSv3 7.8 and users are urged to upgrade to Fusion 26H1 to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
