Threat reportVulnerabilityTL-2026-2340
Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346, CVE-2026-59347)
Broadcom Patches Critical VMware Workstation and Fusion VM (TL-2026-2340) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-09-05 and last reviewed 2026-09-06. It has no confirmed attribution, affects Broadcom VMware Workstation Pro, references 2 CVEs (CVE-2026-59346, CVE-2026-59347), maps to 10 MITRE ATT&CK techniques (T1078.003, T1082, T1203), and is covered by 9 detection rules and 20 indicators of compromise.
- CVSS
- 9.3/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-2340
- Threat ID
- TL-2026-2340
- Severity
- CRITICAL
- CVSS
- 9.3 (AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- information technology, software development, cybersecurity research, government administration, financial services, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
- Updates
- 2026-09-06 · revalidated 1× · latest source
How Broadcom Patches Critical VMware Workstation and Fusion VM works
Broadcom's VMSA-2026-0007 patches two vulnerabilities in VMware Workstation Pro and Fusion (25H2, 26H1): CVE-2026-59346, a CVSS 9.3 integer overflow in the VMXNET3 virtual network adapter, and CVE-2026-59347, a CVSS 8.1 stack-based buffer overflow in HGFS. Either flaw lets an attacker with local administrative privileges inside a guest VM execute code on the host as the VMX process, escaping the sandbox with no workaround available short of upgrading to 26H1u1.
On September 3, 2026, Broadcom published security advisory VMSA-2026-0007 disclosing two guest-to-host escape vulnerabilities in its desktop virtualization products, VMware Workstation Pro and VMware Fusion, versions 25H2 and 26H1 on all supported host platforms (Workstation on Windows/Linux, Fusion on macOS).
CVE-2026-59346 (CVSS 3.1 base score 9.3, vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) is an integer-overflow weakness (CWE-190) in the VMXNET3 paravirtualized network adapter's emulation code. A malicious actor who already holds local administrative privileges on a virtual machine configured with a VMXNET3 adapter can drive the emulated device into an overflow condition and pivot that into arbitrary code execution on the host, i.e. a full VM escape. The low attack complexity (AC:L) and no-privilege-required-on-the-target-component scoring (PR:N), combined with the scope-changed (S:C) confidentiality/integrity/availability-high impact, place this at the top of the CVSS critical band.
CVE-2026-59347 (CVSS 3.1 base score 8.1, vector CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) is a stack-based buffer overflow (CWE-121) in HGFS, the Host-Guest File System component that brokers shared-folder access between a guest and its host. An attacker with local administrative access inside the guest can overflow a stack buffer in the HGFS handling code to execute code with the privileges of the VMX worker process running on the host. The higher attack complexity (AC:H) relative to CVE-2026-59346 accounts for its lower — but still Important-to-Critical range — 8.1 score.
Both issues were privately reported to Broadcom and are credited in VMSA-2026-0007 to independent researcher h4urek (@h4urek) of secsys lab, researchers Y² (@cameudis) and Stan S working through Trend Micro's Zero Day Initiative (also referenced in secondary coverage as "TrendAI Zero Day Initiative") for CVE-2026-59346, and to Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for CVE-2026-59347. Neither Broadcom's advisory nor subsequent press coverage (SecurityWeek, Cyber Security News, Security Affairs, AiCybr, cyberwebspider) reports evidence of in-the-wild exploitation or a public proof-of-concept; both are disclosed as responsibly reported research findings, and Broadcom's advisory does not itself publish explicit CWE identifiers (the CWE-190/CWE-121 classifications used in this record are the standard weakness categories matching the advisory's own "integer overflow" and "stack-based buffer overflow" descriptions).
Notably, CVE-2026-59346's vulnerable component — the VMXNET3 virtual network adapter — is the SAME paravirtualized-device attack surface previously broken in a live demonstration almost exactly one year earlier: per CERT-EU Security Advisory 2025-026 (published 2025-07-18), CVE-2025-41236 (a VMXNET3 integer overflow, also CVSS 9.3) was exploited as a zero-day at Pwn2Own Berlin 2025 (May 2025) alongside CVE-2025-41237 (VMCI integer underflow, CVSS 9.3) and CVE-2025-41238 (PVSCSI heap overflow, CVSS 9.3) — all three in the same VMware Workstation/Fusion desktop-hypervisor emulated-device layer. CVE-2026-59346 is a distinct 2026 vulnerability, not a recurrence of the identical 2025 CWE instance, but the pattern is a meaningful signal for defenders: VMXNET3's emulation code has now produced critical guest-to-host escapes in consecutive years, making it a recurring, high-value target for VM-escape researchers and, potentially, red teams or adversaries targeting isolated analysis/lab environments.
Broadcom shipped VMware Workstation Pro 26H1u1 and VMware Fusion 26H1u1 concurrently with the advisory, resolving both CVE-2026-59346 and CVE-2026-59347. No workaround or mitigating configuration change is available for either flaw — organizations running an affected 25H2 or 26H1 build must upgrade to 26H1u1 to close the exposure. VMSA-2026-0007 was subsequently relayed to the UK health sector by NHS England Digital as cyber alert CC-4841. Because VMware Workstation and Fusion are widely used to host isolated environments for malware analysis, developer sandboxes, and lab/VDI workloads, a guest-to-host escape here is a materially higher-value target than a typical local-privilege bug: it directly undermines the isolation assumption those use cases depend on.
MITRE ATT&CK techniques used in TL-2026-2340
Initial Access
Discovery
T1082 System Information Discovery
Execution
T1203 Exploitation for Client Execution
Stealth
T1211 Exploitation for Stealth
Impact
T1499.004 Application or System Exploitation
Resource Development
T1587.004 Exploits; T1588.005 Exploits
Reconnaissance
T1595.002 Vulnerability Scanning
Privilege Escalation
Defense Impairment
Affected products and versions in Broadcom Patches Critical VMware Workstation and Fusion VM
- Broadcom — VMware Workstation Pro
Vulnerable versions: 25H2; 26H1
Fixed in: 26H1u1 - Broadcom — VMware Fusion
Vulnerable versions: 25H2; 26H1
Fixed in: 26H1u1
Remediation for Broadcom Patches Critical VMware Workstation and Fusion VM
Patches
- VMware Workstation Pro 26H1u1 (VMSA-2026-0007)
- VMware Fusion 26H1u1 (VMSA-2026-0007)
Immediate actions
- Update VMware Workstation Pro and VMware Fusion to version 26H1u1 immediately across all hosts
- Inventory every VMware Workstation/Fusion 25H2 and 26H1 installation in the environment before prioritizing rollout
- Restrict who can hold local administrator rights inside guest VMs, especially VMs used to run untrusted code, malware samples, or third-party/customer workloads
Workarounds
- None available — Broadcom has not published a workaround for either CVE-2026-59346 or CVE-2026-59347; upgrading to 26H1u1 is the only remediation
Longer-term hardening
- Do not treat VMware Workstation/Fusion VMs running untrusted or attacker-controlled code as a hard security boundary until patched to 26H1u1
- Track future Broadcom VMSA advisories for VMware desktop hypervisor products and apply patches on a defined SLA given the pattern of recurring guest-to-host escapes in VMXNET3/VMCI/PVSCSI-class emulated-device components (CVE-2025-41236/-41237/-41238 at Pwn2Own Berlin 2025, CVE-2026-59346/-59347 here)
- Where a guest workload does not require it, avoid attaching a VMXNET3 adapter or enabling HGFS shared folders to reduce the exposed attack surface
CVEs associated with Broadcom Patches Critical VMware Workstation and Fusion VM
CVE-2026-59346, CVE-2026-59347
Weaknesses (CWE) in Broadcom Patches Critical VMware Workstation and Fusion VM
Timeline of Broadcom Patches Critical VMware Workstation and Fusion VM
- At Pwn2Own Berlin 2025, researchers demonstrate live guest-to-host VM escapes against the same VMware Workstation/Fusion emulated-device layer: CVE-2025-41236 (VMXNET3 integer overflow, CVSS 9.3), CVE-2025-41237 (VMCI integer underflow, CVSS 9.3), and CVE-2025-41238 (PVSCSI heap overflow, CVSS 9.3), establishing VMXNET3-class adapters as a recurring VM-escape target roughly a year before CVE-2026-59346.
- CERT-EU publishes Security Advisory 2025-026 documenting the three Pwn2Own Berlin 2025 VMware VM-escape CVEs (CVE-2025-41236/-41237/-41238) for the EU institution community.
- At Pwn2Own Vancouver 2026, Nguyen Hoang Thach of STARLabs SG demonstrates a VMXNET3 out-of-bounds write guest-to-host escape in VMware ESXi (CVE-2026-47876, CVSS 8.2, ZDI-26-495), a second consecutive year in which the VMXNET3 emulated-adapter surface produced a publicly demonstrated VM escape, further corroborating this record's existing assessment of VMXNET3 as a recurring high-value VM-escape target.
- Broadcom confirms no workaround exists for either vulnerability, making the 26H1u1 upgrade the only available remediation.
- Broadcom ships VMware Workstation Pro 26H1u1 and VMware Fusion 26H1u1, resolving both CVE-2026-59346 and CVE-2026-59347.
- Broadcom publishes security advisory VMSA-2026-0007, disclosing CVE-2026-59346 (VMXNET3 integer overflow, CVSS 9.3) and CVE-2026-59347 (HGFS stack buffer overflow, CVSS 8.1) affecting VMware Workstation Pro and Fusion 25H2/26H1.
- VMSA-2026-0007 credits h4urek (secsys lab), Y² (@cameudis) and Stan S via Trend Micro's Zero Day Initiative for CVE-2026-59346, and Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for CVE-2026-59347.
- NHS England Digital relays VMSA-2026-0007 to the UK health sector as cyber alert CC-4841.
- Security Affairs, ISSSource, BeyondMachines, SecurityOnline.info, AiCybr, and cyberwebspider publish coverage of the Broadcom advisory, broadening security-community awareness of the two VM-escape CVEs.
- SecurityWeek and Cyber Security News publish technical breakdowns of the two flaws, noting no evidence of in-the-wild exploitation and no public proof-of-concept code.
Update history for TL-2026-2340
- 2026-09-06 — Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346, CVE-2026-59347): What changed No change. Severity (CRITICAL), exploitability (THEORETICAL), status (PATCHED), CVSS (9.3), and attribution (Unattributed/LOW confidence) all stand as published; no evidence in the newer report supports escalating any of them.
Sources cited for Broadcom Patches Critical VMware Workstation and Fusion VM
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities
- VMSA-2026-0007: VMware Workstation and Fusion updates address CVE-2026-59346, CVE-2026-59347
- VMware Workstation Pro 26H1u1 Release Notes
- VMware Fusion 26H1u1 Release Notes
- VMware Workstation and Fusion Updates Patch Critical Vulnerability
- Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host
- CVE-2026-59346 (CVSS 9.3): VMware Flaw Allows Running Code on the Host
- Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
- VMware Updates Workstation, Fusion Issues
- VMware Workstation and Fusion VMSA-2026-0007: Upgrade to 26H1u1
- VMware Flaws Enable Host Code Execution
- Broadcom Releases Security Advisory for Critical Vulnerabilities in VMware Workstation and VMware Fusion (Cyber Alert CC-4841)
- CERT-EU Security Advisory 2025-026: VMware ESXi, Workstation, Fusion (Pwn2Own Berlin 2025 VM-escape precedent — CVE-2025-41236/-41237/-41238)
- MITRE ATT&CK T1611: Escape to Host
Detection coverage for TL-2026-2340
As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2340 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.