Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-59346: VMware Workstation and Fusion allow VM code execution
CVE-2026-59346 · published 3 days ago
Summary
If someone with administrator rights inside a virtual machine that uses the VMXNET3 network adapter can exploit an integer overflow, they could run code on the underlying host system. This risk affects VMware Workstation versions 25H2 and 26H1, and VMware Fusion versions 25H2 and 26H1. Apply the latest update (26H1u1 or newer) to fix the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vmware | vmware workstation | <= 26H1 |
| vmware | vmware fusion | <= 26H1 |
Original advisory text
VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.
Affected versions:
- VMware Workstation: 25H2, 26H1 (fixed in 26H1u1)
- VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
Affected versions:
- VMware Workstation: 25H2, 26H1 (fixed in 26H1u1)
- VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-190Integer Overflow
Timeline
Published7 Oct 2026
Updated7 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta