VYPR
patchPublished Sep 3, 2026· 1 source

Critical VMware Vulnerabilities Allow VM Escape to Host Code Execution

Two critical vulnerabilities in VMware Workstation and Fusion, CVE-2026-59346 and CVE-2026-59347, allow attackers with local VM admin privileges to execute code on the host system.

Broadcom has released a critical security advisory, VMSA-2026-0007, detailing two severe vulnerabilities affecting VMware Workstation and Fusion. These flaws could enable attackers to escape the confines of a virtual machine and execute malicious code directly on the host operating system, fundamentally compromising the security benefits of virtualization.

The more critical of the two, CVE-2026-59346, is an integer overflow vulnerability within the VMXNET3 virtual network adapter. Rated with a CVSSv3 score of 9.3, this flaw is classified as critical. An attacker who has already obtained administrative privileges within a virtual machine equipped with a VMXNET3 adapter could exploit this vulnerability to achieve code execution on the host machine, effectively breaking out of the virtualized environment.

The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow in the Host-Guest File System (HGFS), which manages file sharing between the virtual machine and the host. This vulnerability, with a CVSSv3 score of 8.1, is rated as important. Successful exploitation would allow an attacker with administrative access inside the guest VM to execute code as the VMX process on the host, providing a pathway to host-level compromise.

Both vulnerabilities were discovered and reported to Broadcom by independent security researchers. CVE-2026-59346 was reported by multiple teams, including h4urek of secsys lab and Y² and Stan S via Trend Micro's Zero Day Initiative. CVE-2026-59347 was reported by Yeonghyeon Choi and Tianchu Chen from Tencent's Xuanwu Lab.

The vulnerabilities affect VMware Workstation versions 25H2 and 26H1, and VMware Fusion versions 25H2 and 26H1, regardless of the host operating system. Broadcom has released version 26H1u1 for both products to address these security issues. Importantly, the advisory states that no workarounds are available for either vulnerability, emphasizing the necessity of immediate patching.

Given that both flaws require only local administrative privileges within a guest VM to achieve host-level compromise, organizations utilizing VMware Workstation or Fusion for sensitive tasks such as malware analysis, testing, or development environments should prioritize this update. The ability to pivot from a contained sandbox directly into production infrastructure makes these vulnerabilities particularly dangerous.

Security administrators are strongly advised to update their VMware Workstation and Fusion installations to version 26H1u1 as soon as possible. In the interim, it is recommended to review and audit which virtual machines are configured with VMXNET3 adapters or utilize the HGFS shared folder feature to assess potential exposure.

Synthesized by Vypr AI