VMware Workstation and Fusion Updates Patch Critical Vulnerability
Broadcom has released updates for VMware Workstation and VMware Fusion to address two security flaws affecting versions 25H2 and 26H1. The most severe issue, identified as CVE-2026-59346 with a CVSS score of 9.3, allows an attacker with local administrator access on a guest VM equipped with a VMXNET3 adapter to execute code on the host via an integer overflow. A second vulnerability, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow that similarly permits code execution within the host's VMX process under specific privilege conditions.
No workarounds are available for these defects, so Broadcom strongly advises users to update to version 26H1u1 immediately. While there is no current evidence of active exploitation and both bugs were reported privately, the frequent targeting of VMware products by threat actors underscores the urgency of applying this patch.