# Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346, CVE-2026-59347)

> Broadcom's VMSA-2026-0007 patches two vulnerabilities in VMware Workstation Pro and Fusion (25H2, 26H1): CVE-2026-59346, a CVSS 9.3 integer overflow in the VMXNET3 virtual network adapter, and CVE-2026-59347, a CVSS 8.1 stack-based buffer overflow in HGFS. Either flaw lets an attacker with local administrative privileges inside a guest VM execute code on the host as the VMX process, escaping the sandbox with no workaround available short of upgrading to 26H1u1.

- **Published:** 2026-09-05T00:00:00Z
- **Last reviewed:** 2026-09-06T18:18:44.916Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2340
- **ID:** TL-2026-2340
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-59346, CVE-2026-59347

## Description

On September 3, 2026, Broadcom published security advisory VMSA-2026-0007 disclosing two guest-to-host escape vulnerabilities in its desktop virtualization products, VMware Workstation Pro and VMware Fusion, versions 25H2 and 26H1 on all supported host platforms (Workstation on Windows/Linux, Fusion on macOS).

CVE-2026-59346 (CVSS 3.1 base score 9.3, vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) is an integer-overflow weakness (CWE-190) in the VMXNET3 paravirtualized network adapter's emulation code. A malicious actor who already holds local administrative privileges on a virtual machine configured with a VMXNET3 adapter can drive the emulated device into an overflow condition and pivot that into arbitrary code execution on the host, i.e. a full VM escape. The low attack complexity (AC:L) and no-privilege-required-on-the-target-component scoring (PR:N), combined with the scope-changed (S:C) confidentiality/integrity/availability-high impact, place this at the top of the CVSS critical band.

CVE-2026-59347 (CVSS 3.1 base score 8.1, vector CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) is a stack-based buffer overflow (CWE-121) in HGFS, the Host-Guest File System component that brokers shared-folder access between a guest and its host. An attacker with local administrative access inside the guest can overflow a stack buffer in the HGFS handling code to execute code with the privileges of the VMX worker process running on the host. The higher attack complexity (AC:H) relative to CVE-2026-59346 accounts for its lower — but still Important-to-Critical range — 8.1 score.

Both issues were privately reported to Broadcom and are credited in VMSA-2026-0007 to independent researcher h4urek (@h4urek) of secsys lab, researchers Y² (@cameudis) and Stan S working through Trend Micro's Zero Day Initiative (also referenced in secondary coverage as "TrendAI Zero Day Initiative") for CVE-2026-59346, and to Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab for CVE-2026-59347. Neither Broadcom's advisory nor subsequent press coverage (SecurityWeek, Cyber Security News, Security Affairs, AiCybr, cyberwebspider) reports evidence of in-the-wild exploitation or a public proof-of-concept; both are disclosed as responsibly reported research findings, and Broadcom's advisory does not itself publish explicit CWE identifiers (the CWE-190/CWE-121 classifications used in this record are the standard weakness categories matching the advisory's own "integer overflow" and "stack-based buffer overflow" descriptions).

Notably, CVE-2026-59346's vulnerable component — the VMXNET3 virtual network adapter — is the SAME paravirtualized-device attack surface previously broken in a live demonstration almost exactly one year earlier: per CERT-EU Security Advisory 2025-026 (published 2025-07-18), CVE-2025-41236 (a VMXNET3 integer overflow, also CVSS 9.3) was exploited as a zero-day at Pwn2Own Berlin 2025 (May 2025) alongside CVE-2025-41237 (VMCI integer underflow, CVSS 9.3) and CVE-2025-41238 (PVSCSI heap overflow, CVSS 9.3) — all three in the same VMware Workstation/Fusion desktop-hypervisor emulated-device layer. CVE-2026-59346 is a distinct 2026 vulnerability, not a recurrence of the identical 2025 CWE instance, but the pattern is a meaningful signal for defenders: VMXNET3's emulation code has now produced critical guest-to-host escapes in consecutive years, making it a recurring, high-value target for VM-escape researchers and, potentially, red teams or adversaries targeting isolated analysis/lab environments.

Broadcom shipped VMware Workstation Pro 26H1u1 and VMware Fusion 26H1u1 concurrently with the advisory, resolving both CVE-2026-59346 and CVE-2026-59347. No workaround or mitigating configuration change is available for either flaw — organizations running an affected 25H2 or 26H1 build must upgrade to 26H1u1 to close the exposure. VMSA-2026-0007 was subsequently relayed to the UK health sector by NHS England Digital as cyber alert CC-4841. Because VMware Workstation and Fusion are widely used to host isolated environments for malware analysis, developer sandboxes, and lab/VDI workloads, a guest-to-host escape here is a materially higher-value target than a typical local-privilege bug: it directly undermines the isolation assumption those use cases depend on.

## MITRE ATT&CK

- T1611 Escape to Host
- T1203 Exploitation for Client Execution
- T1687 Exploitation for Defense Impairment
- T1499.004 Application or System Exploitation
- T1082 System Information Discovery
- T1078.003 Local Accounts
- T1211 Exploitation for Stealth
- T1588.005 Exploits
- T1587.004 Exploits
- T1595.002 Vulnerability Scanning

## Sources

- [Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities](https://securityaffairs.com/198465/security/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities.html)
- [VMSA-2026-0007: VMware Workstation and Fusion updates address CVE-2026-59346, CVE-2026-59347](https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288)
- [VMware Workstation Pro 26H1u1 Release Notes](https://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/workstation-pro/26H1/release-notes/vmware-workstation-pro-26h1u1-release-notes.html)
- [VMware Fusion 26H1u1 Release Notes](https://techdocs.broadcom.com/us/en/vmware-cis/desktop-hypervisors/fusion-pro/26H1/release-notes/vmware-fusion-26h1u1-release-notes.html)
- [VMware Workstation and Fusion Updates Patch Critical Vulnerability](https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/)
- [Critical VMware Workstation and Fusion Vulnerabilities Allow Attackers to Execute Code on the Host](https://cybersecuritynews.com/vmware-workstation-and-fusion-vulnerabilities/)
- [CVE-2026-59346 (CVSS 9.3): VMware Flaw Allows Running Code on the Host](https://securityonline.info/vmware-cve-2026-59346-code-execution-host/)
- [Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion](https://beyondmachines.net/event_details/broadcom-patches-critical-vm-escape-flaws-in-vmware-workstation-and-fusion-n-9-h-5-0)
- [VMware Updates Workstation, Fusion Issues](https://www.isssource.com/vmware-updates-workstation-fusion-issues/)
- [VMware Workstation and Fusion VMSA-2026-0007: Upgrade to 26H1u1](https://aicybr.com/blog/vmware-workstation-fusion-vmsa-2026-0007)
- [VMware Flaws Enable Host Code Execution](https://cyberwebspider.com/cyber-security-news/vmware-vulnerabilities-host-code-execution/)
- [Broadcom Releases Security Advisory for Critical Vulnerabilities in VMware Workstation and VMware Fusion (Cyber Alert CC-4841)](https://digital.nhs.uk/cyber-alerts/2026/cc-4841)
- [CERT-EU Security Advisory 2025-026: VMware ESXi, Workstation, Fusion (Pwn2Own Berlin 2025 VM-escape precedent — CVE-2025-41236/-41237/-41238)](https://cert.europa.eu/publications/security-advisories/2025-026/)
- [MITRE ATT&CK T1611: Escape to Host](https://attack.mitre.org/techniques/T1611/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2340
