Skip to content
Public PoC Exploit for VMware VMXNET3 Vulnerability Released

Public PoC Exploit for VMware VMXNET3 Vulnerability Released

First seen 8 Oct 2026, 12:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 13:30 UTC
  • •CVE-2026-59346 is a critical vulnerability with a CVSS score of 9.3.
  • •The PoC exploit allows guest-to-host code execution for privileged attackers.
  • •A patch has been released in VMware Workstation and Fusion version 26H1u1.

A public proof-of-concept (PoC) exploit has been released for CVE-2026-59346, a critical integer overflow vulnerability in VMware's VMXNET3 virtual network adapter. This flaw allows an attacker with administrative access in a guest virtual machine to execute code on the host system. The vulnerability has a CVSS score of 9.3 and specifically affects the TCP Segmentation Offload (TSO) processing within the vmware-vmx process. Exploitation requires the attacker to first execute high-privileged code in the guest OS. The PoC demonstrates a memory-safety failure that can crash the host's vmware-vmx process. VMware has released a patch in version 26H1u1 to address this vulnerability. This incident follows a previous vulnerability, CVE-2025-41236, which also affected the VMXNET3 adapter. The PoC was published by security researcher Stan S and is available for public use.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-07-15
CVE-2025-41236 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
First public PoC released
Stan S published a public proof-of-concept for CVE-2026-59346 demonstrating the vulnerability.
Gbhackers
2026-10-07
CVE-2026-59346 published
VMware disclosed a critical integer overflow flaw in VMXNET3 with a CVSS score of 9.3.
Gbhackers
2026-10-08
Patch released
VMware released version 26H1u1 to address CVE-2026-59346, urging users to update.
Gbhackers

More articles in this cluster (3)

Following this threat?

Track Broadcom and CVE-2025-41236 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
VMware Workstation and Fusion versions prior to 26H1u1 are affected by CVE-2026-59346.
What does the PoC demonstrate?
The PoC demonstrates a memory-safety failure that can crash the host's vmware-vmx process.
How urgent is the patch?
The patch is critical and should be applied immediately to mitigate the risk of exploitation.