Broadcom has issued a critical security advisory warning that two newly disclosed flaws in VMware Workstation and Fusion could let attackers break out of a virtual machine and run malicious code directly on the underlying host system, a scenario that undermines the core security promise of virtualization.
The advisory, tracked as VMSA-2026-0007 and published on September 3, 2026, details two vulnerabilities affecting VMware’s widely used desktop virtualization products. The more severe of the pair, CVE-2026-59346, is an integer-overflow flaw in the VMXNET3 virtual network adapter. Broadcom rates it at a maximum CVSSv3 score of 9.3, placing it firmly in the critical range.
According to the advisory, a malicious actor who already has local administrative privileges on a virtual machine configured with a VMXNET3 adapter could exploit the flaw to execute code on the host machine itself, effectively escaping the sandboxed VM environment.
The second issue, CVE-2026-59347, is a stack-based buffer-overflow vulnerability in the Host-Guest File System, better known as HGFS, which handles shared folders between a VM and its host.
This flaw carries a CVSSv3 score of 8.1 and is classified as important rather than critical. Exploiting it would allow an attacker with administrative access inside a guest VM to execute code as the VMX process running on the host, giving them a foothold in host-level operations without needing to breach the network adapter directly.
Both vulnerabilities were privately reported to Broadcom rather than discovered through public exploitation, and the company credited multiple independent research teams for the findings.
CVE-2026-59346 was reported separately by researcher h4urek of secsys lab and by Y² and Stan S, working through Trend Micro’s Zero Day Initiative. CVE-2026-59347 was reported by Yeonghyeon Choi and Tianchu Chen of Tencent’s Xuanwu Lab.
The vulnerabilities affect VMware Workstation versions 25H2 and 26H1 running on any host operating system, as well as VMware Fusion versions 25H2 and 26H1 running on macOS.
Broadcom has released version 26H1u1 to remediate both flaws across the affected product lines. Notably, the advisory states there are no workarounds available for either vulnerability, meaning organizations and individual users cannot mitigate the risk through configuration changes alone and must apply the patch to be protected.
Given that both flaws require only local administrative privileges inside a guest VM to trigger a host-level compromise, security teams running VMware Workstation or Fusion in lab, testing, or malware-analysis environments should treat this as a priority patch.
Virtualization platforms are frequently used to isolate untrusted code, and a working VM-escape chain like this one could let attackers pivot from a contained sandbox straight into production infrastructure.
Administrators are advised to update to version 26H1u1 as soon as possible and audit which virtual machines use VMXNET3 adapters or shared folder features in the interim.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host appeared first on Cyber Security News.
