VMware Workstation and Fusion Updates Patch Critical Vulnerability
Broadcom has released patches to address two critical vulnerabilities in VMware Workstation and Fusion, preventing potential code execution and allowing attackers to run malicious code on a host system. These flaws, identified as CVE-2026-59346 and CVE-2026-59347, require immediate updating to mitigate the risk of exploitation.
Broadcom announced the release of security patches to address two significant vulnerabilities within VMware Workstation and Fusion. These vulnerabilities could allow an attacker with local administrative privileges on a virtual machine to execute code on the host system. The first vulnerability, CVE-2026-59346, is an integer overflow that can lead to arbitrary code execution. The second, CVE-2026-59347, is a stack-based buffer overflow with similar potential outcomes, though different exploitation conditions apply. Both flaws affect VMware Workstation and VMware Fusion versions 25H2 and 26H1, and have been resolved in version 26H1u1. Broadcom states that neither vulnerability has been actively exploited in the wild, but acknowledges that security defects in VMware products are frequently targeted by threat actors. Notably, more than two dozen VMware vulnerabilities are currently listed on CISA’s KEV list, highlighting a broader pattern of security concerns within the VMware ecosystem.