TL;DR
Researcher Stan S has published a full analysis and working proof-of-concept for a VMware VMXNET3 vulnerability tracked as CVE-2026-59346. The integer-overflow flaw lets a privileged guest user run code on the host, a classic virtual machine escape. It carries a CVSS score of 9.3, and Broadcom has released a fix in version 26H1u1.
- CVE: CVE-2026-59346
- CVSS: 9.3 (Critical Β· CVSSv3)
- Product: VMware Workstation
- Affected: 25H2
- Impact: VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability
- Status: No confirmed exploitation yet
- Patched in: 26H1u1
- EPSS: 0.3% (30-day)
- Action: Update to 26H1u1 now
Running Infra, AppSec, and SOC teams? Tag VMware alerts by team automatically.
Try Team free for 14 daysWhy It Matters
VMXNET3 is VMware’s paravirtualized network adapter. It is the default NIC for modern guests, so the affected code runs on many systems. A VM escape breaks the core promise of virtualization, which is isolation between a guest and its host.
Crucially, both the details and the exploit code are now public. The full technical write-up walks through the root cause, and a public proof-of-concept repository holds the exploit. That public disclosure raises the urgency for anyone running an unpatched build.
How the Attack Works
The flaw sits in the host’s handling of TCP Segmentation Offload (TSO) packets. According to Broadcom, “a malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.”
At a high level, the host calculates a buffer size by multiplying two values from the guest. That multiplication can overflow a 32-bit register and wrap to a small number. The host then allocates the small, wrapped size but writes far more data into it. The result is a large out-of-bounds write in the host process, filled with guest-controlled bytes.
Notably, this VMware VMXNET3 vulnerability survived an earlier patch. Stan S explains that a 2025 fix for CVE-2025-41236 added bounds checks, but “none of them go anywhere near the multiply that actually decides how large the allocation is.” As a result, values well under the old limits still trigger the overflow.
Exploitation Status
A public proof-of-concept exists, which the researcher’s repository confirms. However, no exploitation in the wild has been reported. CISA’s record also lists exploitation as “none” for now.
The published PoC is limited. The researcher notes it is a “safety violation only and stops at the crash,” causing the VM to power off rather than running attacker code. Even so, the write-up explains how the same bug could be tuned toward code execution, so defenders should not treat it as a mere crash.
Affected Versions
The VMware VMXNET3 vulnerability affects these products:
- VMware Workstation 25H2 and 26H1
- VMware Fusion 25H2 and 26H1 (on macOS)
Both products are fixed in version 26H1u1.
Patch and Mitigation Steps
Upgrade VMware Workstation and Fusion to 26H1u1 or later. The Broadcom security advisory confirms this release closes the flaw. Since the details and PoC are public, the patch is the one durable fix.
Where a patch must wait, reduce risk by limiting who holds administrative rights inside guests. The attack needs that level of access in the VM. Treating guest admin accounts as sensitive narrows the path to this VMware VMXNET3 vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!