Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-06 ยท updated: 2026-09-06 ยท tags: [cve, vm-escape, virtualization, vmware] ยท confidence: high ยท severity: high ยท affected_sectors: [technology] ยท au_impact: false

CVE-2026-59347

Affected product: VMware Workstation and VMware Fusion (versions 25H2 and 26H1)

Patched version: 26H1u1

Active exploitation: None known at disclosure (reported privately to Broadcom)

Assessment

A high-severity stack-based buffer overflow in VMware Workstation and Fusion lets an attacker with local administrative privileges inside a guest virtual machine execute code as the virtual machine's VMX process running on the host. It is the second of two VM-escape flaws patched together (with CVE-2026-59346) and shares the same remediation posture: no workarounds, immediate update to 26H1u1. The absence of an in-the-wild report at disclosure does not reduce urgency, given how frequently VMware desktop and hypervisor flaws become exploitation targets once details and proof-of-concept materialise.