Broadcom released advisory VMSA-2026-0007 addressing two vulnerabilities in VMware Workstation and VMware Fusion for macOS that permit code execution on the host from a privileged guest. CVE-2026-59346, a VMXNET3 integer overflow rated CVSSv3 9.3, allows an attacker with local administrative privileges in a suitably configured virtual machine to execute code on the host. CVE-2026-59347, an HGFS stack-based buffer overflow rated CVSSv3 8.1, allows a guest administrator to execute code in the context of the virtual machine’s VMX process on the host.
Broadcom identifies versions 25H2 and 26H1 as affected and fixes both flaws in 26H1u1, with no workarounds listed. The Canadian Centre for Cyber Security and Guyana National CIRT issued notices urging users and administrators to review the advisory and apply the updates. Organizations should identify affected installations and prioritize upgrading to 26H1u1, particularly where guests are administered by untrusted users. The supplied notices do not report active exploitation.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued notice AV26-1008 concerning the two vulnerabilities affecting VMware Workstation and Fusion for macOS. It directed users and administrators to review the linked advisories and apply necessary updates.
The Zero Day Initiative published an advisory for CVE-2026-59346, assigning it a CVSS score of 7.5 and assessing that exploitation could allow arbitrary code execution in the hypervisor context.
On September 3, 2026, Broadcom published critical advisory VMSA-2026-0007 covering CVE-2026-59346 and CVE-2026-59347, which can allow privileged guest attackers to execute code on the host or as its VMX process. The advisory identifies Workstation and Fusion versions 25H2 and 26H1 as affected, lists 26H1u1 as fixing both vulnerabilities, and provides no workarounds.
0xCyberstan released a public GitHub proof of concept for CVE-2026-59346 that triggers an integer overflow in VMXNET3 TCP Segmentation Offload processing. Requiring administrative privileges inside a guest VM, the PoC demonstrates memory corruption and a vmware-vmx crash that powers off the affected VM, rather than successful guest-to-host code execution.
Guyana National CIRT published a notice referencing VMSA-2026-0007 and Canadian advisory AV26-1008, listing VMware Workstation and Fusion for macOS versions prior to 26H1u1 as affected. It recommended reviewing the updates and applying them where necessary.
Researchers independently reported the VMXNET3 integer-overflow vulnerability CVE-2026-59346 and the HGFS stack-based buffer-overflow vulnerability CVE-2026-59347 to Broadcom. Broadcom credited researchers associated with secsys lab, TrendAI Zero Day Initiative, and Tencent Xuanwu Lab.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
socprime.com
Open sourcethecybersecguru.com
Open sourcethreataft.com
Open sourcecybersecuritynews.com
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourcesupport.broadcom.com
Open sourcesupport.broadcom.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.