Skip to main content

Broadcom Releases Security Advisory for Critical Vulnerabilities in VMware Workstation and VMware Fusion

Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine


Threat details

Introduction

Broadcom has released a security advisory to address two vulnerabilities in VMware Workstation and VMware Fusion.

  • CVE-2026-59346 - 'VMXNET3 integer-overflow' vulnerability - CVSSv3 score of 9.3
  • CVE-2026-59347 - 'HGFS stack buffer-overflow' vulnerability - CVSSv3 score of 8.1

Remediation advice

Affected organisations are encouraged to review Broadcom advisory VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) and apply the relevant update as soon as possible.



Last edited: 3 September 2026 3:10 pm