← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 5, 2026 · 04:54via Security Affairs

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Brief

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately.

Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround.

The first vulnerability, tracked as CVE-2026-59346 (CVSS score of 9. 3), is an integer-overflow vulnerability. The issue resides in the VMXNET3, a virtual network adapter (virtual NIC) designed by VMware for virtual machines.

An attacker with local admin privileges on a virtual machine using a VMXNET3 network adapter could exploit this flaw to run code on the host.

“VMware Workstation and Fusion contain an integer-overflow vulnerability.” reads the advisory .

Read more on Security Affairs