Critical Vulnerabilities Patched in VMware Workstation and Fusion
VMware users have been issued an urgent warning to update their software immediately after Broadcom announced patches for two critical vulnerabilities affecting VMware Workstation and Fusion. The flaws, tracked as CVE-2026-59346 and CVE-2026-59347, could allow attackers with local administrative privileges on a virtual machine to execute arbitrary code on the host.
The first vulnerability is an integer overflow bug that can lead to code execution, while the second is a stack-based buffer overflow that could also result in similar outcomes. Both issues are considered high-severity, with CVE-2026-59346 carrying a CVSS score of 9.3 and CVE-2026-59347 scoring 8.1.
These vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1, but users can breathe a sigh of relief now that Broadcom has released patched versions, including version 26H1u1. Unfortunately, there are no workarounds for either flaw, so updating to the latest iteration is the only way to protect against potential attacks.
It’s worth noting that these vulnerabilities were reported privately to Broadcom and not exploited in the wild at the time of writing. However, security defects in VMware products have been known to be exploited by threat actors in the past. In fact, more than two dozen VMware vulnerabilities are currently included on CISA’s KEV list, highlighting the importance of keeping software up-to-date.
For users who rely on virtual machines for their work or personal projects, updating VMware Workstation and Fusion is a non-negotiable task. The patches are available now, so it’s crucial to prioritize this update as soon as possible to prevent potential security breaches.
In conclusion, while these vulnerabilities were not exploited in the wild, they demonstrate the importance of staying vigilant when it comes to software updates. By prioritizing patching and keeping software up-to-date, users can significantly reduce their exposure to cyber threats.
Source: SecurityWeek — 2026-09-04