CVE-2026-59346
Affected product: VMware Workstation and VMware Fusion (versions 25H2 and 26H1)
Patched version: 26H1u1
Active exploitation: None known at disclosure (reported privately to Broadcom)
Assessment
A critical integer-overflow vulnerability in VMware's VMXNET3 virtual network adapter lets an attacker with local administrative privileges inside a guest virtual machine execute arbitrary code on the host system โ a virtual-machine escape. Combined with CVE-2026-59347 (a stack-based buffer overflow yielding code execution as the VM's VMX process), the pair undermines the isolation guarantee that desktop hypervisors provide to development, security-testing and VDI lab environments. Broadcom states there are no workarounds and recommends immediate update. Australian organisations should treat the patch as mandatory rather than best-effort: desktop virtualisation is common in developer and security-lab environments, and a host-code-execution escape directly undercuts Essential Eight application-control and isolation assumptions.