Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
A critical vulnerability in VMware Workstation and Fusion allows local attackers with administrative privileges to execute arbitrary code on the host machine. Broadcom has released patches to address this issue, alongside another stack-based buffer-overflow vulnerability. This follows a recent campaign targeting VMware vCenter, indicating a continued focus on exploiting VMware products.
Broadcom has released security updates to address a critical vulnerability affecting VMware Workstation and VMware Fusion. The vulnerability, identified as CVE-2026-59346, is an integer-overflow issue that can be exploited by a local attacker with administrative privileges to execute arbitrary code on the host machine. Broadcom stated that a malicious actor with local administrative privileges on a virtual machine equipped with the VMXNET3 virtual network adapter can leverage this flaw.
Another vulnerability, CVE-2026-59347, is a stack-based buffer-overflow vulnerability found in HGFS. This vulnerability can also be exploited by a local attacker with administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.
Both vulnerabilities require an attacker to already possess local administrative privileges, which can be obtained through separate means such as phishing attacks or weak user configurations. The updates, VMware Workstation 26H1u1 and VMware Fusion 26H1u1, provide a solution to these issues.
Broadcom noted that VMware products have been a frequent target for attackers, citing a recent campaign targeting VMware vCenter, where a China-nexus APT group exploited two flaws. This activity impacted 361 unique IP addresses across 47 countries, with a significant concentration in Germany, the U.S., Turkey, Iran, and France.
