Broadcom Patches Critical VMware Workstation and Fusion Flaws That Enable Host Takeover

Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that could let an attacker with administrative privileges inside a virtual machine escape the VM and execute code on the underlying host system, a scenario that undermines the isolation virtualization is meant to provide.

Two Distinct Escape Paths

The more severe issue, tracked as CVE-2026-59346 and carrying a CVSS score of 9.3, is an integer-overflow flaw in how the software handles the VMXNET3 virtual network adapter. According to Broadcom’s advisory, a malicious actor with local administrative privileges on a virtual machine configured with a VMXNET3 adapter can exploit the bug to execute code on the host.

The second flaw, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow in the Host-Guest File System (HGFS), the VMware component that lets a guest VM access files and folders on the physical host. Exploiting it allows code execution as the host’s VMX process, though Broadcom notes the exploitation conditions differ from the first bug.

Patches Available, No Known Exploitation Yet

Both vulnerabilities are fixed in VMware Fusion Pro 26H1u1, released September 3, 2026, and the corresponding Workstation update, detailed in advisory VMSA-2026-0007. CVE-2026-59346 was reported by researchers h4urek, cameudis and Stan S working with Trend’s Zero Day Initiative; CVE-2026-59347 was credited to Yeonghyeon Choi and Tianchu Chen of Tencent’s Xuanwu Lab. As of September 4, Belgium’s national cybersecurity center said it had no indication either flaw was being actively exploited, though it urged administrators to patch immediately given the risk of lateral movement, data exfiltration and host compromise if exploitation conditions are met.

The disclosures follow reports last month that threat actors, including a suspected China-nexus group, were already exploiting separate flaws in VMware vCenter, underscoring sustained attacker interest in Broadcom’s virtualization stack.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *