Vhtforums
AI Assistant
Critical VMware Wor...
 
Notifications
Clear all

Critical VMware Workstation and Fusion vulnerability VMSA-2026-0007 allows VM escape code execution

1 Posts
1 Users
0 Reactions
23 Views
Brandon Lee
Posts: 704
Admin
Topic starter
Translate
English
Spanish
French
German
Italian
Portuguese
Russian
Chinese
Japanese
Korean
Arabic
Hindi
Dutch
Polish
Turkish
Vietnamese
Thai
Swedish
Danish
Finnish
Norwegian
Czech
Hungarian
Romanian
Greek
Hebrew
Indonesian
Malay
Ukrainian
Bulgarian
Croatian
Slovak
Slovenian
Serbian
Lithuanian
Latvian
Estonian
(@brandon-lee)
Member
Joined: 16 years ago
[#549]

If you haven't heard today, Broadcom has published a new Critical VMware security advisory, VMSA-2026-0007, on September 3, 2026. This VMSA covers two vulnerabilities affecting VMware Workstation and VMware Fusion. One of the biggest concerns here is the possibility of escaping from a virtual machine and executing code on the host system.

The thing to call out with this VMSA is that VMware ESXi and vCenter are not listed as affected. This one applies specifically to VMware Workstation and Fusion which is at least good news for the enterprise side of things. The two vulnerabilities are:

CVE-2026-59346: VMXNET3 integer-overflow vulnerability

This is the more serious of the two, carrying a CVSS score of 9.3. According to the VMSA, an attacker with local administrative privileges inside a VM using a VMXNET3 virtual network adapter could potentially escape the VM and execute code on the host system. In other words, this potentially crosses one of the security boundaries that virtualization is supposed to give us. The separation between the guest operating system running in a virtual machine and the host operating system.

CVE-2026-59347: HGFS stack buffer-overflow vulnerability

This vulnerability has a CVSS score of 8.1. This one affects VMware's HGFS functionality. A malicious actor with admin privileges inside a VM can potentially use this one to execute code as the VM's VMX process on the host.

Which versions are affected?

Take note of the following versions affected

  • VMware Workstation 25H2

  • VMware Workstation 26H1

  • VMware Fusion 25H2

  • VMware Fusion 26H1

The fixed release for both products is:

  • VMware Workstation 26H1u1
    VMware Fusion 26H1u1

Workarounds?

None are listed in the VMSA and the remediation is simply to update. 

If you're running VMware Workstation or Fusion, especially on a workstation where you regularly test third-party operating systems, appliances, downloaded VM images, malware samples, or other untrusted workloads, I would put this on the list of things you want to update sooner rather than later. With the VMXNET3 vulnerability, this one is noteworthy since I know I have only used VMXNET3 across the board for years now. So it is hugely common in the VMware world for network connectivity.

This is also another good reminder that the security boundary between the virtual machine and the guest operating system should not automatically be considered perfect. Vulnerabilities in virtual hardware such as network adapters, storage controllers, USB controllers, shared folders, and other emulated devices can definitely happen and possibly provide that path across to the VM boundary.

Recommendation: Update VMware Workstation or Fusion to 26H1u1.

Broadcom advisory:
VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer-overflow vulnerabilities

CVE-2026-59346: CVSS 9.3
CVE-2026-59347: CVSS 8.1
Severity: Critical
Workaround: None
Fixed version: 26H1u1

Read the official advisory here: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288


Leave a reply

Author Name

Author Email

Title *

The advanced attachments is disabled for guests
 
Preview 0 Revisions Saved