Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host
Brief
Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario that undermines the core security promise of virtualization.
The advisory, tracked as VMSA-2026-0007 and published on September 3, 2026, details two vulnerabilities affecting VMware’s widely used desktop virtualization products. The more severe of the pair, CVE-2026-59346, is an integer-overflow flaw in the VMXNET3 virtual network adapter. Broadcom rates it at a maximum CVSSv3 score of 9. 3, placing it firmly in the critical range.
