VMware Workstation and Fusion Vulnerabilities Lead to Critical Security Advisory

VMware Workstation and Fusion Vulnerabilities Lead to Critical Security Advisory

First seen 3 Sep 2026, 14:06 UTC Digital.Nhs.Uksupport.broadcom.comwww.cve.org 72.0

Article Content

Browse articles
ThreatCluster

Broadcom has released a security advisory (VMSA-2026-0007) addressing two critical vulnerabilities in VMware Workstation and Fusion, identified as CVE-2026-59346 and CVE-2026-59347. The first vulnerability, an integer-overflow issue (CVE-2026-59346), has a CVSSv3 score of 9.3 and allows local administrative users on a virtual machine to execute code on the host. The second vulnerability, a stack buffer-overflow (CVE-2026-59347), has a CVSSv3 score of 8.1 and similarly allows code execution as the VMX process on the host. Both vulnerabilities require local administrative privileges to exploit and affect versions 25H2 and 26H2 of VMware Workstation and Fusion. Users are urged to upgrade to version 26H1u1 to remediate these vulnerabilities. The advisory highlights the importance of applying the patches promptly to mitigate potential risks.

Key Points: • Two critical vulnerabilities in VMware Workstation and Fusion disclosed. • CVE-2026-59346 (integer-overflow) has a CVSS score of 9.3. • CVE-2026-59347 (buffer-overflow) has a CVSS score of 8.1.

Timeline

2026-09-03
Security advisory VMSA-2026-0007 released
Broadcom disclosed two critical vulnerabilities in VMware Workstation and Fusion, urging users to apply patches immediately.
support.broadcom.com
2026-09-03
CVE-2026-59346 and CVE-2026-59347 published
Both vulnerabilities were reported and assigned CVSS scores of 9.3 and 8.1, respectively, indicating high severity.
Digital.Nhs.Uk