Broadcom has shipped a maintenance release for VMware Workstation and Fusion that closes two flaws letting code run on the host operating system from inside a virtual machine. Neither issue has a workaround, so moving to version 26H1u1 is the only fix.
The more severe, CVE-2026-59346, is an integer overflow rated 9.3 on the CVSS scale. The prerequisite is local administrative access on a virtual machine running a VMXNET3 adapter; with that, the overflow hands the attacker host-level code execution. The second, CVE-2026-59347, sits at 8.1 and is a stack-based buffer overflow; local admin rights on a VM let the attacker execute code in the VMX process on the host.
The patch, 26H1u1, covers the affected Workstation and Fusion releases, 25H2 and 26H1. Broadcom said the bugs were reported privately and made no mention of exploitation in the wild, though VMware products remain a frequent target, with more than two dozen VMware flaws currently sitting on CISA’s Known Exploited Vulnerabilities catalog.
The guest-to-host boundary these bugs cross is what makes them dangerous: escape chains have historically fed ransomware and espionage campaigns. Admins should treat the update as urgent, verify the running build on every Workstation and Fusion install, and remember that desktop hypervisors in lab and dev fleets are often patched later than production infrastructure.
