Search
Find merged stories by title or summary.
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as CVE-2026-59346 (CVSS score of 9. 3), is an integer-overflow vulnerability. The issue resides in the VMXNET3, a virtual network adapter (virtual NIC) designed by VMware for virtual machines. An attacker with local admin privileges on a virtual machine using a VMXNET3 network adapter could exploit this flaw to run code on the host. “VMware Workstation and Fusion contain an integer-overflow vulnerability.” reads the advisory .
Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host
Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario that undermines the core security promise of virtualization. The advisory, tracked as VMSA-2026-0007 and published on September 3, 2026, details two vulnerabilities affecting VMware’s widely used desktop virtualization products. The more severe of the pair, CVE-2026-59346, is an integer-overflow flaw in the VMXNET3 virtual network adapter. Broadcom rates it at a maximum CVSSv3 score of 9. 3, placing it firmly in the critical range.
You've reached the end of current stories for this search.
