BROADCOM has released patches for two critical vulnerabilities in VMware Workstation and Fusion. The first, tracked as CVE-2026-59346 (CVSS score of 9.3), is an integer overflow that may allow code execution on the host by a malicious actor with local administrative privileges on a virtual machine using a VMXNET3 virtual network adapter. The second vulnerability, CVE-2026-59347 (CVSS score of 8.1), is a stack-based buffer overflow with similar exploit potential under different conditions.
Both issues affect versions 25H2 and 26H1 of the products and are resolved in version 26H1u1. Broadcom recommends immediate updates as there are no workarounds. Currently, there are no indications that these vulnerabilities are being exploited in the wild, but VMware vulnerabilities are frequently targeted by attackers.