Broadcom has released critical updates to address significant security vulnerabilities in VMware Workstation and Fusion, as announced on Thursday. These vulnerabilities include two notable flaws, one of which has been given a CVSS score of 9.3, indicating a severe risk.
Details of the Critical Vulnerabilities
The first vulnerability, identified as CVE-2026-59346, involves an integer overflow issue. This flaw could allow a malicious actor with administrative privileges on a virtual machine utilizing the VMXNET3 virtual network adapter to execute arbitrary code on the host system. Broadcom emphasized the potential risk in their advisory.
The second vulnerability, CVE-2026-59347, with a CVSS score of 8.1, is a stack-based buffer overflow. This flaw, while similar in its potential impact, requires different conditions for exploitation. It allows for code execution through the virtual machine’s VMX process.
Impacted Versions and Updates
Both vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1. The issues have been resolved in version 26H1u1, and users are strongly encouraged to update promptly. Broadcom has made it clear that there are no workarounds available, making the update essential for maintaining security.
While there have been no reports of these vulnerabilities being exploited in the wild, they were disclosed to Broadcom privately. However, given the history of VMware products being targeted by threat actors, timely updates are critical.
Broader Implications and Recommendations
Security vulnerabilities in VMware products are not uncommon. Currently, more than two dozen such vulnerabilities are listed in CISA’s Known Exploited Vulnerabilities (KEV) list. This underlines the importance of addressing these security gaps without delay.
Broadcom’s prompt action in patching these flaws highlights the ongoing battle against cyber threats. Users of VMware Workstation and Fusion are advised to apply these updates immediately to safeguard their systems.
In light of these developments, staying informed about the latest security updates and acting swiftly can mitigate potential risks posed by such vulnerabilities.
