securityonline.info 9/3/2026, 10:35:36 AM · external

CVE-2026-59346 (CVSS 9.3): VMware Flaw Allows Runnin Code on the Host

CVE-2026-59346 (CVSS 9.3): VMware Flaw Allows Runnin Code on the Host
CyberSIXT Evidence Panel

BROADCOM addressed two vulnerabilities in VMware Workstation and Fusion on September 3, 2026. The critical CVE-2026-59346 vulnerability, scoring 9.3 on the CVSS scale, allows attackers with admin rights on a guest VM to execute code on the host system, breaking the security barrier that isolates guest VMs. The second flaw, CVE-2026-59347, is a stack buffer overflow that could also enable code execution on the host, requiring local admin rights.

These vulnerabilities impact VMware Workstation versions 25H2 and 26H1, as well as Fusion on macOS, with patching being the only mitigation available. Both issues had been privately reported, and no public exploits or confirmed exploitation have been reported.

View full article

Article by CyberSIXT