Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-59346: VMware Workstation and Fusion allow VM code execution

CVE-2026-59346 · published 3 days ago
Summary

If someone with administrator rights inside a virtual machine that uses the VMXNET3 network adapter can exploit an integer overflow, they could run code on the underlying host system. This risk affects VMware Workstation versions 25H2 and 26H1, and VMware Fusion versions 25H2 and 26H1. Apply the latest update (26H1u1 or newer) to fix the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
vmware vmware workstation <= 26H1
vmware vmware fusion <= 26H1
Original advisory text
VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.

Affected versions:
- VMware Workstation: 25H2, 26H1 (fixed in 26H1u1)
- VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-190Integer Overflow
Timeline
Published7 Oct 2026
Updated7 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-59346 · MITRE
Track software like this
Free during beta