Critical Vulnerabilities in VMware Workstation and Fusion Patched

Critical Vulnerabilities in VMware Workstation and Fusion Patched

First seen 3 Sep 2026, 14:06 UTC Digital.Nhs.Uksupport.broadcom.comFeeds.FeedburnerSecurityweekCcb.Belgium.Be+4 60.8

Article Content

Browse articles
ThreatCluster

Broadcom has released patches for two critical vulnerabilities in VMware Workstation and Fusion, tracked as CVE-2026-59346 and CVE-2026-59347. The first vulnerability, an integer overflow (CVSS 9.3), allows local administrative users on a VM to execute arbitrary code on the host. The second, a stack-based buffer overflow (CVSS 8.1), also permits code execution under similar conditions. Both vulnerabilities affect versions 25H2 and 26H1, and users are urged to upgrade to version 26H1u1 immediately. No exploitation in the wild has been reported, but the potential for abuse exists given the nature of the flaws. The vulnerabilities were privately reported to Broadcom, and there are no known workarounds available.

Key Points: • Two critical vulnerabilities in VMware Workstation and Fusion patched. • CVE-2026-59346 (integer overflow) has a CVSS score of 9.3. • Immediate upgrade to version 26H1u1 is recommended to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-03
Broadcom releases security advisory
Broadcom published VMSA-2026-0007 detailing two critical vulnerabilities in VMware products.
support.broadcom.com
2026-09-03
NHS issues security alert
The NHS alerted organizations about the vulnerabilities, urging immediate updates to VMware products.
Digital.Nhs.Uk
2026-09-04
Patches released for VMware products
Broadcom announced the release of patches for VMware Workstation and Fusion to address the vulnerabilities.
Feeds.Feedburner