VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347)
38288
03 September 2026
03 September 2026
OPEN
CRITICAL
8.1-9.3
None
CVE-2026-59346, CVE-2026-59347
| Advisory ID: | VMSA-2026-0007 |
| Advisory Severity: | Critical |
| CVSSv3 Range: | 8.1-9.3 |
| Synopsis: | VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) |
| Issue date: | 2026-09-03 |
| Updated on: | 2026-09-03 (Initial Advisory) |
| CVE(s) |
CVE-2026-59346, CVE-2026-59347 |
1. Impacted Products
- VMware Workstation
- VMware Fusion
2. Introduction
An integer-overflow and a buffer-overflow vulnerabilities in VMware Workstation and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.
3a. VMXNET3 integer-overflow vulnerability (CVE-2026-59346)
Description:
VMware Workstation and Fusion contain an integer-overflow vulnerability. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.
Known Attack Vectors:
A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.
Resolution:
To remediate CVE-2026-59346 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None
Additional Documentation:
None.
Acknowledgments:
Broadcom would like to thank h4urek(@h4urek) with secsys lab & Y² (@cameudis) and Stan S working with TrendAI Zero Day Initiative for independently reporting this issue to us.
Notes:
None.
3b. HGFS stack buffer-overflow vulnerability (CVE-2026-59347)
Description:
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. Broadcom has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.1.
Known Attack Vectors:
A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Resolution:
To remediate CVE-2026-59347 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds:
None
Additional Documentation:
None.
Acknowledgments:
Broadcom would like to thank Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for independently reporting this issue to us.
Notes:
None.
Response Matrix 3a and 3b:
| VMware Product | Version | Running On | CVE | CVSSv3 | Severity | Fixed Version | Workarounds | Additional Documentation |
| VMware Workstation | 25H2, 26H1 | Any |
CVE-2026-59346, CVE-2026-59347 |
9.3, 8.1 | Critical | 26H1u1 | None | None |
| VMware Fusion | 25H2, 26H1 | MacOS |
CVE-2026-59346, CVE-2026-59347 |
9.3, 8.1 | Critical | 26H1u1 | None | None |
4. References
VMware Workstation 26H1u1
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productdownloads?subfamily=VMware%20Workstation%20Pro&freeDownloads=true
https://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/workstation-pro/26H1/release-notes/vmware-workstation-pro-26h1u1-release-notes.html
VMware Fusion 26H1u1
Downloads and Documentation:
https://support.broadcom.com/group/ecx/productfiles?subFamily=VMware%20Fusion&displayGroup=VMware%20Fusion%2026H1&release=26H1&os=&servicePk=543219&language=EN&freeDownloads=true
https://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/fusion-pro/26H1/release-notes/vmware-fusion-26h1u1-release-notes.html
Mitre CVE Dictionary Links:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59346
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-59347
FIRST CVSSv3 Calculator:
CVE-2026-59346: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE-2026-59347: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
5. Change Log:
2026-09-03 VMSA-2026-0007
Initial security advisory.
6. Contact:
E-mail: [email protected]
PGP key
https://knowledge.broadcom.com/external/article/321551
VMware Security Advisories
https://www.broadcom.com/support/vmware-security-advisories
VMware External Vulnerability Response and Remediation Policy
https://www.broadcom.com/support/vmware-services/security-response
VMware Lifecycle Support Phases
https://support.broadcom.com/group/ecx/productlifecycle
VMware Security Blog
https://blogs.vmware.com/security
X
https://x.com/VMwareSRC
Copyright 2026 Broadcom. All rights reserved.