Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom patches two VMware vulnerabilities with CVSS scores of 9.3 and 8.1, allowing arbitrary code execution and buffer overflow.
Intelligence analysis by Qwen 2.5 (3B)

Broadcom has patched two VMware vulnerabilities, CVE-2026-59346 and CVE-2026-59347, with CVSS scores of 9.3 and 8.1, respectively, which could lead to arbitrary code execution and buffer overflow.
These vulnerabilities in VMware tools could let bad guys run their own code on your computer if they already have special powers on your computer.
Analysis
{"
Broadcom's Response to the Vulnerabilities":"Broadcom has released security updates for VMware Workstation and Fusion, addressing two critical flaws. The first vulnerability, CVE-2026-59346, has a CVSS score of 9.3 and allows arbitrary code execution under certain conditions. The second vulnerability, CVE-2026-59347, has a CVSS score of 8.1 and involves a stack-based buffer overflow. Both vulnerabilities require local administrative privileges to exploit.","
The Impact of the Vulnerabilities":"The vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1. Broadcom has patched these vulnerabilities in VMware Workstation 26H1u1 and VMware Fusion 26H1u1. The vulnerabilities were discovered by @h4urek, @cameudis, and Stan S for CVE-2026-59346, and by Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for CVE-2026-59347. The vulnerabilities have not been exploited in the wild, but vulnerabilities in VMware products have been an attack magnet.","
The Attack Vector":"Successful exploitation of the vulnerabilities requires an attacker to already possess local administrative privileges. However, these privileges can be obtained through separate compromises, such as phishing or exploiting weak user configurations. The vulnerabilities affect VMware Workstation and Fusion, which are widely used virtualization tools."}
Key points
- Broadcom patched two VMware vulnerabilities with CVSS scores of 9.3 and 8.1
- The vulnerabilities affect VMware Workstation and Fusion versions 25H2 and 26H1
- Successful exploitation requires local administrative privileges
- The vulnerabilities have not been exploited in the wild, but they are an attack magnet
- Users should update their VMware tools to protect against these risks
The patches should help prevent attackers from using these vulnerabilities to cause harm. Users should update their VMware tools to protect against these risks.
If attackers manage to exploit these vulnerabilities, they could run their own code on users' computers, which could be dangerous. Users should stay vigilant and keep their software updated.



