CVE-2026-59347
Affected product: VMware Workstation and VMware Fusion (versions 25H2 and 26H1)
Patched version: 26H1u1
Active exploitation: None known at disclosure (reported privately to Broadcom)
Assessment
A high-severity stack-based buffer overflow in VMware Workstation and Fusion lets an attacker with local administrative privileges inside a guest virtual machine execute code as the virtual machine's VMX process running on the host. It is the second of two VM-escape flaws patched together (with CVE-2026-59346) and shares the same remediation posture: no workarounds, immediate update to 26H1u1. The absence of an in-the-wild report at disclosure does not reduce urgency, given how frequently VMware desktop and hypervisor flaws become exploitation targets once details and proof-of-concept materialise.