Broadcom has released security updates addressing two vulnerabilities affecting VMware Workstation and VMware Fusion, including a critical flaw that could allow attackers to execute arbitrary code on the host system under specific conditions. The most severe vulnerability, tracked as CVE-2026-59346 with a CVSS score of 9.3, is an integer-overflow issue that could be exploited by a local attacker with elevated privileges to run unauthorized code.
According to Broadcom, an attacker with local administrative privileges on a virtual machine configured with a VMXNET3 virtual network adapter could exploit the vulnerability to execute code on the host operating system. The company disclosed the issue in a security alert and credited security researchers @h4urek, @cameudis, and Stan S for identifying and reporting the flaw. The vulnerability highlights the importance of maintaining updated virtualization environments, as virtual machines often serve as critical infrastructure components across enterprise environments. Broadcom has also addressed another security issue affecting VMware Workstation and VMware Fusion, identified as CVE-2026-59347 with a CVSS score of 8.1. This vulnerability is a stack-based buffer-overflow flaw found in the Host Guest File Sharing (HGFS) component. A malicious actor with local administrative privileges inside a virtual machine could exploit the issue to execute code as the virtual machine VMX process running on the host system. The flaw was reported by Yeonghyeon Choi and Tianchu Chen from Tencent Xuanwu Lab, who were acknowledged by Broadcom for their contribution to improving VMware security.
In both cases, successful exploitation requires an attacker to already have local administrative privileges within the affected virtual machine. Such access could potentially be gained through separate security incidents, including phishing campaigns or weak user configurations that allow unauthorized access. Broadcom noted that there are no available workarounds for these vulnerabilities and recommended users upgrade to the patched versions, VMware Workstation 26H1u1 and VMware Fusion 26H1u1. The vulnerabilities impact VMware Workstation and VMware Fusion versions 25H2 and 26H1. While Broadcom has not found evidence that these particular flaws have been exploited in active attacks, vulnerabilities in VMware products have continued to attract attention from threat actors due to their potential impact on enterprise systems and virtualized environments.
Recently, VMware infrastructure was targeted through the exploitation of two vulnerabilities affecting VMware vCenter, identified as CVE-2026-59309 and CVE-2026-59310. Security researchers observed active exploitation shortly after the flaws were publicly disclosed, with the latter vulnerability linked to suspected activity by a China-nexus advanced persistent threat actor. The campaign reportedly began five calendar days after public disclosure and affected 361 unique victim IP addresses across 47 countries. The highest number of affected systems were reported in Germany, followed by the United States, Turkey, Iran, and France. The latest security updates from Broadcom reinforce the need for organizations using VMware virtualization products to apply available patches promptly and review access controls across virtual machine environments. Keeping administrative privileges restricted and ensuring proper security configurations remain essential steps in reducing the risk associated with virtualization vulnerabilities.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





