488/69 Monday, September 7, 2026

Broadcom has published security advisory VMSA-2026-0007 to address two vulnerabilities in VMware Workstation and VMware Fusion that could allow an attacker inside a virtual machine (VM) to execute code on the underlying host. One of the vulnerabilities is rated Critical, and no workaround is available to reduce the risk. The vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. VMware Workstation runs on Windows and Linux, while VMware Fusion runs on macOS. Broadcom has fixed both vulnerabilities in version 26H1u1 and recommends that users update as soon as possible.
The first vulnerability, CVE-2026-59346, has a CVSS score of 9.3 and is an integer overflow vulnerability in VMXNET3, a virtual network adapter, or virtual NIC, designed by VMware for use in virtual machines. An attacker with local administrator privileges on a VM using the VMXNET3 network adapter could exploit the vulnerability to execute code on the host. The vulnerability was reported to the vendor by researcher h4urek from secsys lab, Y², and Stan S through Trend Micro’s Zero Day Initiative.
The second vulnerability, CVE-2026-59347, has a CVSS score of 8.1 and is a stack-based buffer overflow vulnerability in the Host-Guest File System (HGFS) component, a VMware feature that allows guest VMs to access files and directories on the physical host. An attacker with local administrator privileges on a VM could exploit this vulnerability to execute code with the privileges of the VMX process running on the host. The vulnerability was reported by Yeonghyeon Choi and Tianchu Chen from Tencent Xuanwu Lab. Since no workarounds are available for either vulnerability, administrators should promptly update VMware Workstation and Fusion to version 26H1u1 to reduce the risk of VM escape attacks.
