TL;DR
Broadcom patched two VMware Workstation and Fusion flaws on September 3, 2026. The more severe VMware Workstation vulnerability, CVE-2026-59346, scores 9.3 CVSS. An attacker with admin rights inside a guest VM could break out and execute code on the host.
Why It Matters
Workstation and Fusion run guest VMs on desktops and laptops. Many people use them to detonate untrusted code in isolation. Therefore, a guest-to-host escape breaks that core safety boundary.
This VMware Workstation vulnerability lets malware leave the sandbox. As a result, a compromised VM could reach the underlying machine. Broadcom rates the advisory Critical.
How the Attack Works
CVE-2026-59346 is an integer-overflow bug in the VMXNET3 virtual network adapter. The advisory states a local admin on such a VM “may exploit this issue to execute code on the host”.
The second flaw, CVE-2026-59347, is a stack buffer overflow in HGFS. Broadcom says it could run code “as the virtual machine’s VMX process running on the host”. Both need local admin rights inside the guest. This report withholds exploit detail.
Exploitation Status
Both issues were privately reported to Broadcom. No exploitation in the wild has been confirmed. Likewise, no public proof-of-concept exists at publication. Multiple research teams, including Zero Day Initiative and Tencent Xuanwu Lab, are credited.
Affected Versions
The flaws affect VMware Workstation 25H2 and 26H1 on any host. They also affect VMware Fusion 25H2 and 26H1 on macOS. VMXNET3 must be in use for the first flaw.
Patch and Mitigation Steps
No workarounds exist, so patching is the only fix. Update both Workstation and Fusion to version 26H1u1.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!