BROADCOM has patched two critical vulnerabilities in VMware Workstation and Fusion, tracked as CVE-2026-59346 and CVE-2026-59347, which could allow an attacker to execute code on the host from within a virtual machine. The first issue is an integer-overflow vulnerability (CVSS score 9.3) affecting the VMXNET3 virtual network adapter, while the second one is a stack-based buffer overflow in the Host-Guest File System (HGFS) with a CVSS score of 8.1.
Both vulnerabilities require local administrative privileges on the virtual machine to exploit and have no workarounds. Users are urged to update to version 26H1u1 immediately.