Vulnerability
Published 2026-09-03
Verified 2026-09-19

VMware Workstation/Fusion VMSA-2026-0007: VMXNET3 integer overflow and HGFS stack overflow (CVE-2026-59346/59347)

Broadcom VMSA-2026-0007 (3 September 2026, Critical) patches two privately reported host-escape-class bugs in VMware Workstation and VMware Fusion 25H2 and 26H1. CVE-2026-59346 is a VMXNET3 integer overflow (CVSSv3 up to 9.3) where a malicious actor with local administrative privileges inside a guest that uses the VMXNET3 virtual NIC may execute code on the host. CVE-2026-59347 is an HGFS stack-based buffer overflow (CVSSv3 up to 8.1) that can let a guest admin run code as the VMX process on the host. Fixed in Workstation and Fusion 26H1u1. No workarounds. Broadcom does not report in-the-wild exploitation. Update lab and desktop hypervisors promptly; these are not ESXi/vSphere guest escape advisories.

Product
VMware Workstation and VMware Fusion
Versions
25H2 and 26H1 before 26H1u1
CVSS
9.3 / 8.1 (CVSSv3, Broadcom)
Exploited in Australia?
unknown
Patch to
Workstation and Fusion 26H1u1 (or later)

Primary: Broadcom VMSA-2026-0007 (3 Sep 2026) · Vendor: Broadcom / VMware (vendor) · CVE: CVE-2026-59346, CVE-2026-59347 · SecurityWeek (4 Sep 2026)

vulnerabilities cloud