Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Overview
Broadcom has issued security updates to address two vulnerabilities in VMware Workstation and VMware Fusion, one of which is particularly severe. This critical vulnerability, identified as CVE-2026-59346, has a CVSS score of 9.3 and involves an integer-overflow issue. If exploited by a local attacker with elevated privileges, this flaw could allow them to execute arbitrary code on the host system. This poses a significant risk to users of these virtualization products, as it could lead to unauthorized access and control over the host machine. Users are urged to apply the updates promptly to mitigate this risk.
Key Takeaways
- Affected Systems: VMware Workstation, VMware Fusion
- Action Required: Users should update to the latest versions of VMware Workstation and VMware Fusion as provided in the security updates from Broadcom.
- Timeline: Newly disclosed
Original Article Summary
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
Impact
VMware Workstation, VMware Fusion
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users should update to the latest versions of VMware Workstation and VMware Fusion as provided in the security updates from Broadcom. Specific patch numbers or versions were not mentioned in the article.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, VMware, Exploit, and 2 more.