Broadcom Releases Security Advisory for Critical Vulnerabilities in VMware Workstation and VMware Fusion
Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine
Summary
Security advisory addresses vulnerabilities that could lead to arbitrary code execution on a host system from an affected virtual machine
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Broadcom has released a security advisory to address two vulnerabilities in VMware Workstation and VMware Fusion.
- CVE-2026-59346 - 'VMXNET3 integer-overflow' vulnerability - CVSSv3 score of 9.3
- CVE-2026-59347 - 'HGFS stack buffer-overflow' vulnerability - CVSSv3 score of 8.1
Remediation advice
Affected organisations are encouraged to review Broadcom advisory VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) and apply the relevant update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 September 2026 3:10 pm