VMware Patches Critical Flaw That Lets VM Users Break Out to the Host Machine
Broadcom has released security updates for two vulnerabilities in VMware Workstation and Fusion, one of which is rated critical. The most severe issue, CVE-2026-59346 (CVSS 9.3), is an integer-overflow flaw that a local attacker with elevated privileges could exploit to execute arbitrary code on the host machine, provided the virtual machine uses a VMXNET3 virtual network adapter.
The second flaw, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer-overflow bug in HGFS that could let an attacker with local admin rights on a VM run code as the host's VMX process. Both flaws require the attacker to already have local administrative privileges on the virtual machine, which could be gained through phishing or weak account configurations elsewhere. There are no workarounds, but fixes are available in VMware Workstation 26H1u1 and VMware Fusion 26H1u1.
While Broadcom says there is no evidence of active exploitation of these two flaws, VMware products remain a popular target. Just last month, attackers were seen actively exploiting separate VMware vCenter vulnerabilities, with one reportedly used by a China-linked group to breach hundreds of organisations worldwide.