News

VMware patches host escape bugs in Workstation and Fusion

Broadcom VMSA-2026-0007 patches CVE-2026-59346 (VMXNET3 integer overflow, CVSS 9.3) and CVE-2026-59347 (HGFS stack overflow, 8.1) in Workstation and Fusion 25H2 and 26H1. Fixed in 26H1u1. No workarounds. Privately reported, no wild-use claim.

VMware patches host escape bugs in Workstation and Fusion

Broadcom published VMware Security Advisory VMSA-2026-0007 on 3 September 2026, a Critical notice for Workstation and Fusion. The advisory scores the pair at CVSS 8.1 to 9.3 and ships one fixed build, 26H1u1. This is a vendor patch notice. It is not a CISA Known Exploited Vulnerabilities listing for these two CVE IDs.

CVE-2026-59346 is a VMXNET3 integer overflow, Critical at 9.3, so an actor with local admin on a guest that uses the VMXNET3 adapter may execute code on the host. CVE-2026-59347 is an HGFS stack buffer overflow, Important at 8.1, so local admin on a guest may execute code as that VM's VMX process on the host. HGFS is the shared-folders path.

Both bugs hit Workstation 25H2 and 26H1 on any OS, and Fusion 25H2 and 26H1 on macOS. Broadcom lists no workarounds for either CVE. Labs that leave HGFS or VMXNET3 on untrusted guests have only the 26H1u1 bump.

The advisory says both issues were privately reported. It does not claim exploitation in the wild. SecurityWeek notes that many other VMware defects already sit on CISA's KEV list. That is background on the product family, not a claim about CVE-2026-59346 or CVE-2026-59347.

These two IDs are a different job from the already-exploited Chrome V8 type confusion, the SonicWall SMA 1000 zero-days, and the JFrog Artifactory auth bypass. The closer cousin is the Cisco Nexus 9000 Silicon One root RCE: a vendor critical with a patch and no public wild-use claim in the notice itself.

Bump VMware Workstation and Fusion to 26H1u1 on every analyst laptop today. Until that build is installed, do not grant local admin inside untrusted guests that use VMXNET3 or HGFS.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free