Critical Vulnerabilities Patched in VMware Workstation and Fusion
Broadcom has released urgent security updates for **VMware Workstation** and **VMware Fusion**, addressing two significant vulnerabilities. One of these, a critical integer-overflow flaw, could allow a local attacker with elevated privileges to execute arbitrary code on the host system. IT security professionals are strongly advised to patch immediately.

**Broadcom** has issued critical security updates for its **VMware Workstation** and **VMware Fusion** virtualization products. These patches address two security flaws, with one posing a significant risk of arbitrary code execution.
### Critical Integer-Overflow Flaw
The most severe vulnerability, tracked as **CVE-2026-59346** (CVSS score: 9.3), is an integer-overflow bug. A local attacker who has obtained elevated privileges on a virtual machine equipped with a **VMXNET3** virtual network adapter could exploit this flaw to execute arbitrary code on the host system.
**Broadcom** acknowledged @h4urek, @cameudis, and Stan S for their discovery of this critical issue.
### Stack-Based Buffer-Overflow in HGFS
Also addressed is **CVE-2026-59347** (CVSS score: 8.1), a stack-based buffer-overflow vulnerability affecting **HGFS** (Host Guest File System). Similar to the first flaw, this vulnerability requires an attacker to have local administrative privileges on a virtual machine. Successful exploitation could lead to code execution as the virtual machine's **VMX** process running on the host.
Yeonghyeon Choi and Tianchu Chen of **Tencent Xuanwu Lab** were credited for reporting this vulnerability.
### Prerequisites for Exploitation
For both vulnerabilities, successful exploitation hinges on the attacker already possessing local administrative privileges within the guest virtual machine. While this is a prerequisite, such privileges can be acquired through other means, such as phishing attacks or exploiting weak user configurations.
### Affected Versions and Patches
The vulnerabilities impact **VMware Workstation** and **VMware Fusion** versions 25H2 and 26H1. **Broadcom** has confirmed that there are no workarounds for these issues, emphasizing the importance of applying the released patches. The vulnerabilities have been resolved in **VMware Workstation 26H1u1** and **VMware Fusion 26H1u1**.
### History of VMware Exploitation
While there is no current evidence of these specific flaws being exploited in the wild, **VMware** products have historically been a frequent target for threat actors. As recently as last month, attackers were observed actively exploiting two other vulnerabilities in **VMware vCenter**, **CVE-2026-59309** and **CVE-2026-59310**.
One of these, **CVE-2026-59310**, is suspected to have been weaponized by a China-nexus advanced persistent threat (APT) actor. This campaign, which began just five days after public disclosure, reportedly breached 361 unique IP addresses across 47 countries, with significant concentrations in Germany, the U.S., Turkey, Iran, and France.
Given this history, IT security professionals are urged to prioritize the immediate application of these new **Broadcom** patches to safeguard their virtualized environments.