Critical Vulnerability Patched in VMware Workstation and Fusion Updates – Stay Secure

www.news4hackers.com-critical-vulnerability-patched-in-vmware-workstation-and-fusion-updates-stay-secure-critical-vulnerability-patched-in-vmware-workstation-and-fusion-updates-stay-secure

Critical vulnerabilities in VMware Workstation and Fusion have been resolved with new patches, addressing significant risks of unauthorized code execution on host systems.

Overview of the Vulnerabilities

Broadcom disclosed updates on Thursday to resolve two high-severity flaws impacting VMware Workstation and Fusion. The vulnerabilities, designated CVE-2026-59346 and CVE-2026-59347, pose significant risks due to their potential to enable unauthorized code execution on host systems.

CVE-2026-59346: Integer Overflow Vulnerability

The first issue, CVE-2026-59346, involves an integer overflow vulnerability within the VMXNET3 virtual network adapter. This flaw could allow a malicious actor with administrative access to a virtual machine to execute arbitrary code on the underlying host. The severity of this vulnerability is rated 9.3 on the CVSS scale.

CVE-2026-59347: Stack-Based Buffer Overflow

The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow that similarly permits code execution. However, the conditions required for exploitation differ, as this flaw targets the VMX process running on the host. Both vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1.

Patches and Recommendations

Patches were included in version 26H1u1, which users are strongly advised to deploy immediately. No temporary mitigations are available, and Broadcom has not confirmed any active exploitation of these issues in the wild. The company stated that the flaws were reported through private channels.

“The disclosure highlights ongoing concerns about VMware products being targeted by threat actors. Over two dozen VMware-related vulnerabilities are currently listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog.”

Broader Implications

Security teams are urged to prioritize patching to prevent potential exploitation. The updates follow a broader trend of critical flaws being addressed across enterprise software. Recent reports have also highlighted exploits targeting other platforms, underscoring the importance of timely remediation. Organizations using affected VMware versions should verify their software is updated to the latest release to mitigate risks.



About Author

en_USEnglish