Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine
Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine
The following platforms are known to be affected:
VMware Workstation and Fusion
Note: Upgrading to version 26H1u1 will remediate both 25H2 and 26H2 on VMware Workstation and Fusion.
Broadcom has released a security advisory to address two vulnerabilities in VMware Workstation and VMware Fusion.
CVE-2026-59346 - 'VMXNET3 integer-overflow' vulnerability - CVSS v3 score of 9.3
CVE-2026-59347 - 'HGFS stack buffer-overflow' vulnerability - CVSSv3 score of 8.1
Affected organisations are encouraged to review Broadcom advisory VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) and apply the relevant update as soon as possible.
Definitive source of threat updates
Last edited: 3 September 2026 2:57 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
