Digital.Nhs.Uk
Critical Vulnerabilities in VMware Workstation and Fusion Patched
Article Content
Broadcom has released patches for two critical vulnerabilities in VMware Workstation and Fusion, tracked as CVE-2026-59346 and CVE-2026-59347. The first vulnerability, an integer overflow (CVSS 9.3), allows local administrative users on a VM to execute arbitrary code on the host. The second, a stack-based buffer overflow (CVSS 8.1), also permits code execution under similar conditions. Both vulnerabilities affect versions 25H2 and 26H1, and users are urged to upgrade to version 26H1u1 immediately. No exploitation in the wild has been reported, but the potential for abuse exists given the nature of the flaws. The vulnerabilities were privately reported to Broadcom, and there are no known workarounds available.
Key Points: • Two critical vulnerabilities in VMware Workstation and Fusion patched. • CVE-2026-59346 (integer overflow) has a CVSS score of 9.3. • Immediate upgrade to version 26H1u1 is recommended to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.