Skip to content
CC-4841

CC-4841

Digital.Nhs.Uk [email protected] (NHS Digital) September 3, 2026

Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine

Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine

The following platforms are known to be affected:

VMware Workstation and Fusion

Note: Upgrading to version 26H1u1 will remediate both 25H2 and 26H2 on VMware Workstation and Fusion.

Broadcom has released a security advisory to address two vulnerabilities in VMware Workstation and VMware Fusion.

CVE-2026-59346 - 'VMXNET3 integer-overflow' vulnerability - CVSS v3 score of 9.3

CVE-2026-59347 - 'HGFS stack buffer-overflow' vulnerability - CVSSv3 score of 8.1

Affected organisations are encouraged to review Broadcom advisory VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) and apply the relevant update as soon as possible.

Definitive source of threat updates

Last edited: 3 September 2026 2:57 pm