CVE Tools
Back to feed
Patch released VMware Workstation privilege-escalation VMware Fusion Broadcom rce

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Broadcom has issued security updates for VMware Workstation and VMware Fusion to remediate two distinct vulnerabilities, including a critical integer-overflow flaw. The primary issue, identified as CVE-2026-59346 with a CVSS score of 9.3, permits a local administrator within a guest virtual machine using the VMXNET3 adapter to execute arbitrary code on the host system.

Additionally, a high-severity stack-based buffer overflow in HGFS (CVE-2026-59347, CVSS 8.1) was addressed, allowing similar privilege escalation to the host's VMX process. Both flaws affect versions 25H2 and 26H1 of the software, and users should update to the fixed releases, VMware Workstation 26H1u1 and VMware Fusion 26H1u1, as no workarounds are available.