logo

Root Access Race: TOCTOU Vulnerability (CVE-2026-41702) Hits VMware Fusion

ID: 0345594d-fad8-5d32-a510-79351d4b8aa6

STIX ID: report--0345594d-fad8-5d32-a510-79351d4b8aa6

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

Broadcom released patches for VMware Fusion addressing CVE-2026-41702, a TOCTOU (time-of-check/time-of-use) local privilege escalation in a SETUID binary affecting Fusion 25H2; a local attacker can potentially escalate to root. The issue is rated CVSSv3 7.8 and users are urged to upgrade to Fusion 26H1 to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.