Skip to content
VMware Workstation and Fusion Updates Patch Critical Vulnerability

VMware Workstation and Fusion Updates Patch Critical Vulnerability

Feeds.Feedburner Ionut Arghire September 4, 2026

Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion.

The first issue, tracked as CVE-2026-59346 (CVSS score of 9.3), is described as an integer overflow bug leading to arbitrary code execution.

“A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” Broadcom notes in its advisory .

Tracked as CVE-2026-59347 (CVSS score of 8.1), the second flaw is a stack-based buffer overflow that could lead to similar outcomes, albeit the exploitation conditions are different.

“A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host,” Broadcom explains.

Both vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1 and were resolved in version 26H1u1.

There are no workarounds for either of the flaws, and Broadcom recommends updating to a patched iteration as soon as possible.

The company makes no mention of any of these vulnerabilities being exploited in the wild, and says that both issues were reported to it privately.

However, security defects in VMware products are often exploited by threat actors . More than two dozen VMware vulnerabilities are currently included in CISA’s KEV list .

Related: CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

Related: Exploit Published for Fresh Cleo Harmony Vulnerability

Related: SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

Related: Hackers Start Exploiting Critical Langflow Vulnerability

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Exploit Published for Fresh Cleo Harmony Vulnerability

Malicious Virtualizor Update Served via BGP Hijacking

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

23-Year-Old Sality P2P Botnet Disrupted

Hackers Start Exploiting Critical Langflow Vulnerability

Five Venezuelans Plead Guilty in US Court to ATM Jackpotting

Ransomware Gang Claims Nutex Health Data Breach

9.5 Million Impacted by Aesto Health Data Breach

Google Patches 6th Chrome Zero-Day of 2026

Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

HiddenLayer Raises $100 Million for AI Runtime Security

AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million

153 Million Driver License Images Offered on Dark Web

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Virtual Event: Attack Surface Management Summit 2026

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover?

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Flipboard Whatsapp Whatsapp Email