On September 4, 2026, Broadcom released security updates for its VMware Workstation and Fusion products, addressing two vulnerabilities that could lead to a virtual machine (VM) escape. The most critical flaw, CVE-2026-59346, is an integer overflow in the VMXNET3 virtual network adapter with a CVSS score of 9.3. It allows an attacker with local administrative privileges on a guest VM to execute arbitrary code on the host operating system. A second high-severity flaw, CVE-2026-59347, was also fixed. There is no evidence of active exploitation, but due to the severity, users are strongly advised to update to the patched versions immediately.
Two vulnerabilities were addressed in this update:
CVE-2026-59346: This is a critical integer overflow vulnerability in the VMXNET3 virtual network adapter component. It received a CVSSv3 score of 9.3. An attacker who has already compromised a guest VM and obtained administrative privileges can exploit this flaw to trigger an integer overflow, leading to a memory corruption condition that can be leveraged to execute arbitrary code on the underlying host system. This constitutes a full VM escape.
CVE-2026-59347: This is a high-severity stack-based buffer overflow vulnerability with a CVSSv3 score of 8.1. Similar to the first flaw, an attacker must have local administrative privileges on the guest VM. Exploitation allows the attacker to execute code within the context of the VM's VMX process on the host, which is a less privileged context than the host kernel but still represents a significant security boundary breach.
The following VMware products are affected:
Broadcom has released version 26H1u1 for both product lines to address these vulnerabilities.
As of the disclosure, Broadcom stated there is no indication that these vulnerabilities have been exploited in the wild. Both flaws were reported through private disclosure channels. However, vulnerabilities in virtualization platforms are highly sought after by advanced threat actors for espionage and by ransomware groups for deeper network infiltration. The lack of current exploitation does not diminish the urgency to patch.
The primary impact of these vulnerabilities is a complete loss of security segmentation between a guest virtual machine and the host operating system. An attacker who successfully exploits CVE-2026-59346 can break out of the virtualized environment and gain control over the host machine. This is particularly dangerous in multi-tenant environments, development labs, or any scenario where untrusted code runs inside a VM. A compromised host could lead to the compromise of all other VMs running on it, as well as access to the broader corporate network to which the host is connected.
The following patterns may help identify vulnerable or compromised systems:
vmware-vmx.exe on Windows). This could include the VMX process spawning shells (cmd.exe, bash) or making unusual network connections.The primary mitigation is to apply the security patches provided by Broadcom, as no workarounds are available.
Mapped D3FEND Techniques:
Limiting administrative privileges within the guest VM is a critical prerequisite for exploitation and acts as a compensating control.
Isolating the host management interface from networks accessible by the guest VM can help contain an attacker post-escape.
The only effective defense against CVE-2026-59346 and CVE-2026-59347 is to immediately apply the patches provided by Broadcom. Organizations must update all instances of VMware Workstation and Fusion to version 26H1u1 or later. Prioritize patching on systems where the host machine is critical or where guest VMs run untrusted code, such as in development, sandboxing, or multi-tenant environments. Use enterprise patch management systems to automate deployment and verify completion. Since no workarounds exist, patching is a mandatory and urgent action to prevent a complete security boundary collapse between guest and host.
As a critical compensating control, enforce the principle of least privilege within all guest virtual machines. Exploitation of both CVE-2026-59346 and CVE-2026-59347 requires the attacker to first gain local administrative privileges on the guest OS. By restricting admin access, organizations significantly raise the bar for an attacker. Conduct regular audits of user accounts and permissions inside VMs, removing any unnecessary administrative rights. This control does not fix the vulnerability but disrupts the attack chain, making successful exploitation much more difficult and providing an opportunity for detection before a VM escape can occur.
Broadcom releases security updates for VMware Workstation and Fusion to patch two vulnerabilities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.