Skip to main content
CybersecurityVulnerability Management

Broadcom Patches VMware Flaws That Expose Hosts to Code Execution

Server room with rows of computer servers and networking equipment, focusing on a central server rack with a VMXNET3…
"A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host," Broadcom said in an alert.

CVE-2026-59346: an integer-overflow that jumps the VM boundary

Broadcom has assigned CVE-2026-59346 a CVSS score of 9.3 and described it as an integer-overflow vulnerability in the VMXNET3 virtual network adapter implementation. According to the advisory, exploitation requires a local attacker who already has elevated privileges inside a virtual machine. If exploited under those conditions, the bug can allow an attacker to run arbitrary code on the host — effectively escaping the guest to execute at the host level. Broadcom credited the discovery to three researchers identified as @h4urek, @cameudis, and Stan S.

CVE-2026-59347: HGFS stack-based buffer overflow affecting the VMX process

Broadcom also patched CVE-2026-59347, a stack-based buffer-overflow vulnerability in HGFS with a CVSS score of 8.1. The company said a bad actor with local administrative privileges on a virtual machine could exploit this flaw to execute code as the virtual machine's VMX process on the host. The report acknowledges Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for reporting that issue.

Affected products, versions and the available updates

The two vulnerabilities impact VMware Workstation and VMware Fusion versions 25H2 and 26H1. Broadcom said there are no workarounds that mitigate either vulnerability and that fixes have been released in VMware Workstation 26H1u1 and VMware Fusion 26H1u1. Broadcom framed the risk narrowly — both bugs require that an attacker already possess local administrative privileges inside a guest — but also noted those privileges can be obtained through separate compromises such as phishing or weak user configurations.

Recent context: active exploitation of VMware vCenter flaws

Although Broadcom said there is no evidence that the Workstation and Fusion vulnerabilities have been exploited in the wild, the advisory places these patches into a tense context. As recently as last month, threat actors were observed actively exploiting two different VMware vCenter vulnerabilities — CVE-2026-59309 and CVE-2026-59310. That campaign began five calendar days after one of the flaws was publicly disclosed and is estimated to have breached 361 unique victim IP addresses across 47 countries. The largest concentrations of those infections were in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25). Broadcom’s advisory also notes that CVE-2026-59310 was suspected to have been weaponized by a China-nexus advanced persistent threat (APT) actor, underlining that VMware product vulnerabilities have been an active target for attackers.

What this means for technologists, enterprises, and adversaries

  • Technologists and security teams: With no mitigations available short of patching, teams running VMware Workstation or Fusion should prioritize updating to VMware Workstation 26H1u1 and VMware Fusion 26H1u1. The advisory’s emphasis that the exploits require local administrative privileges nevertheless makes containment of credential compromise and hardening of guest systems relevant to risk reduction.
  • Affected enterprises and procurement leaders: Organizations that permit desktop virtualization or that issue preconfigured virtual machines should account for the absence of workarounds when assessing exposure for users who run versions 25H2 and 26H1. The recent vCenter exploit timeline — weaponization within days of disclosure and hundreds of infected IPs across dozens of countries — is a reminder that VMware product flaws can draw fast, widespread attention from threat actors.
  • Adversaries and threat actors: The requirement for local admin rights does not eliminate the appeal of these bugs. Broadcom itself points out that those rights can be obtained by separate compromises such as phishing or misconfiguration, and prior campaigns against VMware vCenter show a pattern of rapid exploitation once a vulnerability is public.

Broadcom has published patches and named the researchers involved, but the advisory closes on two facts that will drive immediate decision-making for defenders: there are no workarounds, and recent history shows VMware vulnerabilities can be weaponized quickly and broadly. Whether attackers will follow the same path for these Workstation and Fusion flaws is an open question; the practical answer for many teams is already clear — apply the VMware Workstation 26H1u1 and VMware Fusion 26H1u1 updates as soon as possible and treat guest administrative access as a high-value control point.

https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html