Particle.news

Broadcom Patches Two VM‑Escape Flaws in VMware Workstation and Fusion

The fixes close an integer‑overflow in the VMXNET3 virtual NIC and an HGFS stack overflow that allowed a VM administrator to execute code on the host.

Overview

  • Broadcom released fixes in VMware Workstation and Fusion version 26H1u1 that resolve CVE-2026-59346 (integer overflow, CVSS 9.3) and CVE-2026-59347 (HGFS stack buffer overflow, CVSS 8.1).
  • Both flaws let a user with administrative privileges inside a guest virtual machine run code on the physical host, creating a VM‑to‑host escape risk that targets the VMX process or host runtime.
  • There are no workarounds for either vulnerability and Broadcom says the issues were privately reported; administrators are urged to update to 26H1u1 immediately to remediate the holes.
  • Broadcom credited multiple independent researchers for the reports and noted there is no confirmed evidence of these CVEs being exploited in the wild, though recent rapid weaponization of other VMware bugs raises urgency.
  • The flaws affect Workstation on Windows and Linux and Fusion on macOS for versions 25H2 and 26H1, and successful attacks require prior local admin access inside the guest—meaning phishing, privilege escalation, or weak configurations remain key attack vectors.