type: incident ยท created: 2026-09-06 ยท updated: 2026-09-06 ยท tags: [incident, cve, vm-escape, virtualization, vmware] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false
Broadcom Patches Two VM-Escape Flaws in VMware Workstation and Fusion
Summary
Broadcom patched two vulnerabilities in its VMware Workstation and Fusion desktop hypervisors that let an attacker with local administrative privileges inside a guest virtual machine escape to execute code on the host.
Key Facts
- CVE-2026-59346 (CVSS 9.3): integer overflow reachable via the VMXNET3 virtual network adapter; arbitrary code execution on the host.
- CVE-2026-59347 (CVSS 8.1): stack-based buffer overflow; code execution as the VM's VMX process on the host.
- Affected: Workstation and Fusion versions 25H2 and 26H1; fixed in 26H1u1.
- Remediation: No workarounds; immediate update recommended. Neither flaw known to be exploited in the wild at disclosure.
Significance
The pair extends a concentrated week of critical-detail and in-the-wild disclosures across VMware, Citrix, SonicWall, Chrome and CrowdStrike products, and lands on the desktop-virtualisation surface common to developer and security-lab environments where host-code-execution undermines isolation assumptions.
Related Pages
- CVE-2026-59346
- CVE-2026-59347