VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)
VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)
VMware Fusion VMware Workstation
CVE-2026-59346, CVE-2026-59347
CVE-2026-59346, CVE-2026-59347
An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstatio and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.
3a. VMXNET3 integer-overflow vulnerability (CVE-2026-59346)
Description: VMware Workstation and Fusion contain an integer-overflow vulnerability. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3 .
Known Attack Vectors: A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.
Resolution: To remediate CVE-2026-59346 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Additional Documentation: None.
Acknowledgments: Broadcom would like to thank h4urek(@h4urek) with secsys lab & Y² (@cameudis) and Stan S working with TrendAI Zero Day Initiative for independently reporting this issue to us.
3b. HGFS stack buffer-overflow vulnerability (CVE-2026-59347)
Description: VMware contain a stack-based buffer-overflow vulnerability in HGFS. Broadcom has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.1 .
Known Attack Vectors: A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Resolution: To remediate CVE-2026-59347 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Additional Documentation: None.
Acknowledgments: Broadcom would like to thank Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for independently reporting this issue to us.
Response Matrix 3a and 3b:
CVE-2026-59346, CVE-2026-59347
CVE-2026-59346, CVE-2026-59347
VMware Workstation 26H1u1 Downloads and Documentation:
VMware Fusion 26H1u1 Downloads and Documentation:
Mitre CVE Dictionary Links:
FIRST CVSSv3 Calculator: CVE-2026-59346: CVE-2026- 59347 :
2026-09-03 VMSA-2026-0007 Initial security advisory.
E-mail: [email protected] PGP key VMware Security Advisories VMware External Vulnerability Response and Remediation Policy VMware Lifecycle Support Phases VMware Security Blog X
It appears your Broadcom Products and Services are supported by one of our certified Support partners
Click below to be redirected to the appropriate Support Partner Portal to request support
For Technical Support (issues with products or services)
Select Technical to be redirected to the My Entitlements page
Expand the product you require support on
Select the case icon from the case column
You will be redirected to the appropriate vendor portal where you can raise your technical request
For Non-Technical Support (issues with portal access, license keys, software downloads)
Select Non-Technical to be redirected to Broadcom's case management portal
To prevent this message from showing again, please enable pop-up blockers for support.broadcom.com or click Continue to proceed.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
