securityonline.info 8 Oct 2026, 02:16 UTC

VMware Patches Critical VM Escape Flaw After Public PoC Release

VMware Patches Critical VM Escape Flaw After Public PoC Release
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

VMWARE Workstation and Fusion VMXNET3 Flaw CVE-2026-59346 has been disclosed with a full technical write‑up and a public proof-of-concept. The integer‑overflow vulnerability can allow a privileged guest user to run code on the host, effectively escaping the virtual machine. The issue carries a CVSS of 9.3 (Critical, CVSSv3) and was patched by Broadcom in VMware’s 26H1u1 update. Affected products include VMware Workstation 25H2 and 26H1, and VMware Fusion 25H2 and 26H1 (on macOS). The fix is included in 26H1u1.

Exploitation status is currently limited to a public PoC repository and a formal write‑up; there are no reported instances of exploitation in the wild, and CISA records exploitation as “none” for now. The PoC described in the disclosure demonstrates a potential path to code execution but is noted by researchers as a safety‑oriented proof of concept that crashes the VM (the host powers off).

The vulnerability resides in how the host handles TCP Segmentation Offload (TSO) packets on the VMXNET3 network adapter; a 32‑bit overflow during a guest‑provided size calculation can lead to a large, out‑of‑bounds write in the host process.

Remediation guidance focuses on upgrading to 26H1u1 or newer. Where patching is not yet possible, restricting guest administrative privileges can reduce risk, since the attack requires admin rights inside the VM.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline