Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
VMware Vulnerabilities Allow Host Code Execution

VMware Vulnerabilities Allow Host Code Execution

Posted on September 3, 2026 By CWS

Broadcom has issued a crucial security advisory concerning two recently identified vulnerabilities in VMware Workstation and Fusion. These flaws pose a significant risk as they enable attackers to escape from a virtual machine (VM) and execute malicious code on the underlying host system. This development challenges the fundamental security assurances provided by virtualization technology.

Details of the Security Flaws

The advisory, labeled VMSA-2026-0007 and released on September 3, 2026, highlights two vulnerabilities affecting VMware’s desktop virtualization solutions. The more critical of the two, CVE-2026-59346, involves an integer-overflow issue in the VMXNET3 network adapter. This flaw has been assigned a CVSSv3 score of 9.3, indicating its critical severity.

As outlined in the advisory, an attacker with local administrative rights on a VM that uses a VMXNET3 adapter can exploit this flaw to run code on the host machine. This allows the attacker to breach the VM’s sandboxed environment.

Understanding the Second Vulnerability

The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow in the Host-Guest File System (HGFS), which manages shared folders between a VM and the host. This flaw has a CVSSv3 score of 8.1 and is considered important rather than critical. Exploiting it enables an attacker with administrative access within a guest VM to execute code as the VMX process on the host, thus gaining unauthorized access to host-level operations.

These vulnerabilities were reported to Broadcom by independent research teams, rather than being identified through public exploitation. CVE-2026-59346 was reported by h4urek of secsys lab and researchers Y² and Stan S through Trend Micro’s Zero Day Initiative. CVE-2026-59347 was reported by Yeonghyeon Choi and Tianchu Chen from Tencent’s Xuanwu Lab.

Impact and Mitigation Measures

The vulnerabilities impact VMware Workstation versions 25H2 and 26H1 on any host OS, and VMware Fusion versions 25H2 and 26H1 on macOS. Broadcom has released version 26H1u1 to address these flaws. Notably, no workarounds are available, making the patch essential for protection.

Given that these vulnerabilities only necessitate local administrative rights within a guest VM to compromise the host, it is imperative for security teams using VMware Workstation or Fusion in testing or malware-analysis environments to prioritize this update.

Virtualization platforms are integral for isolating untrusted code, and a breach of this nature could allow attackers to move from a contained environment into production systems. Administrators should immediately upgrade to version 26H1u1 and review which VMs utilize VMXNET3 adapters or shared folder functionalities.

In conclusion, ensuring timely updates is critical to mitigate risks associated with these vulnerabilities and maintain the integrity of virtualization infrastructure.

Cyber Security News Tags:Broadcom, CVE-2026-59346, CVE-2026-59347, Cybersecurity, Fusion, HGFS, host code execution, Patch, Security, Virtualization, VMware, VMXNET3, Vulnerabilities, Workstation

Post navigation

Previous Post: AIR Security Unveils AI Firewall with $50M Funding
Next Post: US Leads in Global Phishing Scheme Targeting 46 Nations

Related Posts

Russian Basketball Player Arrested over Alleged Ransomware Attack Claims Russian Basketball Player Arrested over Alleged Ransomware Attack Claims Cyber Security News
NVIDIA GPU Display Driver Vulnerabilities Allows Code Execution and Privilege Escalation NVIDIA GPU Display Driver Vulnerabilities Allows Code Execution and Privilege Escalation Cyber Security News
Critical Cybersecurity Updates: Microsoft, Cisco, and More Critical Cybersecurity Updates: Microsoft, Cisco, and More Cyber Security News
Phishing Campaign Targets U.S. Firms with Fake Invitations Phishing Campaign Targets U.S. Firms with Fake Invitations Cyber Security News
New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users Cyber Security News
Critical Bing Images Flaws Patched Amid Security Concerns Critical Bing Images Flaws Patched Amid Security Concerns Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GPT-6 Astra Unveiled: Revolutionizing Cybersecurity Testing
  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams
  • Claude AI Outage Disrupts Key Models and Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GPT-6 Astra Unveiled: Revolutionizing Cybersecurity Testing
  • Affordable SweepLED Device Detects Hidden Cameras in Hotels
  • FBI Investigates Massive Driver’s License Leak on Dark Web
  • Hackers Exploit QR Codes in Phishing Scams
  • Claude AI Outage Disrupts Key Models and Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark