VMware Workstation & Fusion Critical Flaws Patched

Broadcom Patches Critical VMware VM Escape Vulnerabilities

CRITICAL
September 5, 2026
4m read
VulnerabilityPatch ManagementCloud Security

Related Entities

Organizations

BroadcomCISA

Products & Tech

VMware Workstation VMware FusionVMXNET3

CVE Identifiers

CVE-2026-59346
CRITICAL
CVSS:9.3
CVE-2026-59347
HIGH
CVSS:8.1

Full Report

Executive Summary

On September 4, 2026, Broadcom released security updates for its VMware Workstation and Fusion products, addressing two vulnerabilities that could lead to a virtual machine (VM) escape. The most critical flaw, CVE-2026-59346, is an integer overflow in the VMXNET3 virtual network adapter with a CVSS score of 9.3. It allows an attacker with local administrative privileges on a guest VM to execute arbitrary code on the host operating system. A second high-severity flaw, CVE-2026-59347, was also fixed. There is no evidence of active exploitation, but due to the severity, users are strongly advised to update to the patched versions immediately.


Vulnerability Details

Two vulnerabilities were addressed in this update:

  • CVE-2026-59346: This is a critical integer overflow vulnerability in the VMXNET3 virtual network adapter component. It received a CVSSv3 score of 9.3. An attacker who has already compromised a guest VM and obtained administrative privileges can exploit this flaw to trigger an integer overflow, leading to a memory corruption condition that can be leveraged to execute arbitrary code on the underlying host system. This constitutes a full VM escape.

  • CVE-2026-59347: This is a high-severity stack-based buffer overflow vulnerability with a CVSSv3 score of 8.1. Similar to the first flaw, an attacker must have local administrative privileges on the guest VM. Exploitation allows the attacker to execute code within the context of the VM's VMX process on the host, which is a less privileged context than the host kernel but still represents a significant security boundary breach.

Affected Systems

The following VMware products are affected:

  • VMware Workstation versions 25H2 and 26H1
  • VMware Fusion versions 25H2 and 26H1

Broadcom has released version 26H1u1 for both product lines to address these vulnerabilities.

Exploitation Status

As of the disclosure, Broadcom stated there is no indication that these vulnerabilities have been exploited in the wild. Both flaws were reported through private disclosure channels. However, vulnerabilities in virtualization platforms are highly sought after by advanced threat actors for espionage and by ransomware groups for deeper network infiltration. The lack of current exploitation does not diminish the urgency to patch.

Impact Assessment

The primary impact of these vulnerabilities is a complete loss of security segmentation between a guest virtual machine and the host operating system. An attacker who successfully exploits CVE-2026-59346 can break out of the virtualized environment and gain control over the host machine. This is particularly dangerous in multi-tenant environments, development labs, or any scenario where untrusted code runs inside a VM. A compromised host could lead to the compromise of all other VMs running on it, as well as access to the broader corporate network to which the host is connected.

Cyber Observables — Hunting Hints

The following patterns may help identify vulnerable or compromised systems:

  • Monitor host systems for any anomalous processes originating from the VMX process (e.g., vmware-vmx.exe on Windows). This could include the VMX process spawning shells (cmd.exe, bash) or making unusual network connections.
  • Analyze host system logs for unexpected crashes or restarts of the VMX process, which could indicate failed exploitation attempts.
  • On the guest VM, look for the loading of unusual drivers or modules related to the VMXNET3 adapter, although a sophisticated attacker would likely try to hide these activities.

Detection Methods

  • Asset Inventory and Version Scanning: The most reliable detection method is to maintain an accurate inventory of all systems running VMware Workstation and Fusion. Use vulnerability scanners or asset management tools to identify all instances running affected versions (25H2 and 26H1).
  • Host-based Monitoring: Deploy EDR solutions on host machines to monitor the behavior of the VMX process. Create detection rules for any suspicious child processes or file modifications initiated by the VMX process.
  • Network Segmentation Monitoring: While not a direct detection method for the exploit, monitoring for violations of network segmentation policies between the guest VM and the host's management network can be an indicator of lateral movement following a successful escape.

Remediation Steps

  • Apply Updates: Broadcom has confirmed that there are no workarounds for these vulnerabilities. The only effective remediation is to update to the patched versions:
    • VMware Workstation 26H1u1
    • VMware Fusion 26H1u1
  • Prioritize Patching: Prioritize patching for hosts that run VMs exposed to the internet or accessible by untrusted users. Development environments and systems used by security researchers should also be considered high priority.
  • Restrict Guest Admin Access: As a general best practice, limit administrative access within guest VMs to only authorized personnel. This is a prerequisite for exploitation and serves as a strong compensating control.

Timeline of Events

1
September 4, 2026
Broadcom releases security updates for VMware Workstation and Fusion to patch two vulnerabilities.
2
September 5, 2026
This article was published

MITRE ATT&CK Mitigations

The primary mitigation is to apply the security patches provided by Broadcom, as no workarounds are available.

Mapped D3FEND Techniques:

Limiting administrative privileges within the guest VM is a critical prerequisite for exploitation and acts as a compensating control.

Mapped D3FEND Techniques:

Isolating the host management interface from networks accessible by the guest VM can help contain an attacker post-escape.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The only effective defense against CVE-2026-59346 and CVE-2026-59347 is to immediately apply the patches provided by Broadcom. Organizations must update all instances of VMware Workstation and Fusion to version 26H1u1 or later. Prioritize patching on systems where the host machine is critical or where guest VMs run untrusted code, such as in development, sandboxing, or multi-tenant environments. Use enterprise patch management systems to automate deployment and verify completion. Since no workarounds exist, patching is a mandatory and urgent action to prevent a complete security boundary collapse between guest and host.

As a critical compensating control, enforce the principle of least privilege within all guest virtual machines. Exploitation of both CVE-2026-59346 and CVE-2026-59347 requires the attacker to first gain local administrative privileges on the guest OS. By restricting admin access, organizations significantly raise the bar for an attacker. Conduct regular audits of user accounts and permissions inside VMs, removing any unnecessary administrative rights. This control does not fix the vulnerability but disrupts the attack chain, making successful exploitation much more difficult and providing an opportunity for detection before a VM escape can occur.

Timeline of Events

1
September 4, 2026

Broadcom releases security updates for VMware Workstation and Fusion to patch two vulnerabilities.

Sources & References

VMware Workstation and Fusion Updates Patch Critical Vulnerability
SecurityWeek (securityweek.com) September 4, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

VM escapevirtualization securityinteger overflowbuffer overflowVMwareBroadcom

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.