Gbhackers Public PoC Exploit for VMware VMXNET3 Vulnerability Released
Article Content
- •CVE-2026-59346 is a critical vulnerability with a CVSS score of 9.3.
- •The PoC exploit allows guest-to-host code execution for privileged attackers.
- •A patch has been released in VMware Workstation and Fusion version 26H1u1.
A public proof-of-concept (PoC) exploit has been released for CVE-2026-59346, a critical integer overflow vulnerability in VMware's VMXNET3 virtual network adapter. This flaw allows an attacker with administrative access in a guest virtual machine to execute code on the host system. The vulnerability has a CVSS score of 9.3 and specifically affects the TCP Segmentation Offload (TSO) processing within the vmware-vmx process. Exploitation requires the attacker to first execute high-privileged code in the guest OS. The PoC demonstrates a memory-safety failure that can crash the host's vmware-vmx process. VMware has released a patch in version 26H1u1 to address this vulnerability. This incident follows a previous vulnerability, CVE-2025-41236, which also affected the VMXNET3 adapter. The PoC was published by security researcher Stan S and is available for public use.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Broadcom and CVE-2025-41236 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
What does the PoC demonstrate?
How urgent is the patch?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…