Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround.
The first vulnerability, tracked as CVE-2026-59346 (CVSS score of 9.3), is an integer-overflow vulnerability. The issue resides in the VMXNET3, a virtual network adapter (virtual NIC) designed by VMware for virtual machines.
An attacker with local admin privileges on a virtual machine using a VMXNET3 network adapter could exploit this flaw to run code on the host.
“VMware Workstation and Fusion contain an integer-overflow vulnerability.” reads the advisory. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.”
Researchers h4urek(@h4urek) with secsys lab & Y² (@cameudis) and Stan S, working with TrendAI Zero Day Initiative, independently reported this flaw to the vendor.
The second issue, tracked as CVE-2026-59347 (CVSS score of 8.1), is a stack-based buffer overflow in HGFS component. Host-Guest File System (HGFS) is a VMware feature that lets a virtual machine (guest) access files and directories located on the physical host.
An attacker with local administrator privileges on a virtual machine could exploit this flaw to execute code with the privileges of the VMX process running on the host.
“VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS.” continues the advisory. “A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host.”
Researchers Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab reported the vulnerability to Broadcom.
The vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. Workstation runs on Windows and Linux, while Fusion runs on macOS. VMware fixed both flaws in version 26H1u1.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Broadcom )