Critical Integer-Overflow Vulnerability in VMware Workstation and Fusion Enables Host Code Execution
A critical integer-overflow vulnerability (CVE-2026-59346, CVSS 9.3) and a stack-based buffer-overflow vulnerability (CVE-2026-59347, CVSS 8.1) in VMware Workstation and Fusion enable host code execution when exploited by attackers with local administrative privileges on virtual machines. Both flaws have been patched in versions 26H1u1, but no workarounds exist and previous VMware vulnerabilities have been actively exploited in the wild.
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.
The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.
"A
*** END OF TRANSMISSION ***