Broadcom Fixes Critical VMware Workstation and Fusion Flaw

Broadcom released the 26H1u1 update for VMware Workstation and Fusion. It addresses the critical vulnerability CVE-2026-59346, which under specific conditions could allow code execution from a virtual machine on the host.

The CVE-2026-59346 vulnerability in VMware is a critical flaw for which Broadcom released security updates for VMware Workstation and VMware Fusion on September 3, 2026. Under precisely defined conditions, the flaw could allow an attacker to execute code on the host operating system from a virtual machine. The fix is available in version 26H1u1 for both products.

CVE-2026-59346 VMware: Conditions for a Possible VM Escape

According to the VMSA-2026-0007 security advisory, CVE-2026-59346 is an integer overflow vulnerability with a maximum CVSSv3 score of 9.3. However, successful exploitation is not a remote attack or a scenario in which an ordinary virtual-machine account would be sufficient.

The attacker must have local administrative privileges in the guest virtual machine, and the VM must use a VMXNET3 virtual network adapter. If these prerequisites are met, the vulnerability could lead to code execution on the host system.

This therefore represents a possible escape from the isolated virtual-machine environment to the computer running Workstation or Fusion. This type of flaw is particularly significant because the separation between guest and host is one of virtualization’s fundamental security properties.

Security Advisory Also Addresses an HGFS Flaw

In the same security advisory, Broadcom also fixed CVE-2026-59347. This vulnerability is a stack-based buffer overflow in HGFS and has a maximum CVSSv3 score of 8.1.

Broadcom does not list a workaround for these vulnerabilities. Users should therefore deploy the fixed version 26H1u1 rather than relying on temporary configuration measures.

Who Is Affected by the Update

The update is intended for devices running VMware Workstation 25H2 or 26H1 and VMware Fusion 25H2 or 26H1. Administrators should verify the version in use and update to 26H1u1, especially if untrusted users or workloads could obtain administrative privileges inside their virtual machines.

The precise conditions are important in this case. Describing the flaw simply as a problem “for VM admins” does not capture its full scope: CVE-2026-59346 requires administrative privileges directly in the guest VM as well as a VMXNET3 network adapter.

Active Exploitation Has Not Been Confirmed So Far

Broadcom does not state in the security advisory that CVE-2026-59346 or CVE-2026-59347 is being actively exploited. The available information therefore does not confirm attacks in practice. Further developments could bring technical details from researchers, a proof of concept, or a notification from security authorities or the vendor about exploitation.

For desktop virtualization administrators, the immediate step is to check Workstation and Fusion installations and deploy version 26H1u1 wherever affected releases are in use.

Sources

  • Broadcom VMSA-2026-0007 – Confirms the advisory date, affected products, attack conditions, CVSS, the absence of a workaround, and fixed version 26H1u1.
  • The Hacker News – Independently summarizes the release of the security updates and the critical classification of CVE-2026-59346.

Verified and updated: 09/05/2026 21:23

Sharing