
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Severity : Critical (CVE-2026-59346)
CVSS v3.1 Score : 9.3

Information
VMware Workstation and Fusion is virtualization software developed by VMware for creating and managing virtual machines (VMs) on physical computers. It provides a virtualized computing environment that allows users to install and run multiple operating systems on a single computer, such as Windows, Linux, and other supported operating systems. VMware Workstation is primarily designed for Windows and Linux, while VMware Fusion is designed for macOS. The software is commonly used for system testing, software development, server virtualization, and creating IT and cybersecurity laboratory environments. It also allows users to configure and manage virtual machine resources, including CPU, memory, storage, and network settings, providing a flexible environment for testing and system management.
Incident
CVE-2026-59346 is a Critical-severity security vulnerability affecting VMware Workstation and VMware Fusion in the VMXNET3 Virtual Network Adapter component. The vulnerability is classified as an Integer Overflow issue caused by improper validation and processing of data associated with VMXNET3. An attacker who has access to a Guest Virtual Machine and Local Administrator privileges within the VM may be able to send specially crafted data to trigger the vulnerability, potentially leading to Arbitrary Code Execution in the context of the Hypervisor/Host.
This vulnerability is particularly significant because it may lead to VM Escape, allowing an attacker to escape the boundaries of a Virtual Machine and gain access to the VMware Host. If successfully exploited, the attacker may be able to access Host resources, including other Virtual Machines running on the same Host. This could impact the Confidentiality, Integrity, and Availability (CIA) of the systems, potentially resulting in data access or theft, data modification or destruction, malware installation, persistence, and the use of the compromised Host as a starting point for further attacks or Lateral Movement to other systems within the organization.
However, this vulnerability cannot be directly exploited from the Internet to attack the VMware Host. The attacker must first have access to the Guest VM and possess Local Administrator privileges within the VM before they can attempt to exploit the vulnerability.
Affected Products and Versions
•VMware Workstation 25H2
•VMware Workstation 26H1
•VMware Fusion 25H2
•VMware Fusion 26H1
Recommendation
•Upgrade to the following versions
•VMware Workstation 26H1u1
•VMware Fusion 26H1u1
References
•https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html?m=1
•https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/
•https://nexusvoidai.com/cyber-news/vmware-workstation-fusion-cve-2026-59346-host-escape