Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
Two high-severity vulnerabilities could allow guest VM administrators to execute arbitrary code on the host system.
Broadcom has released urgent security updates to address two critical VM-escape vulnerabilities affecting VMware Workstation and Fusion. These flaws allow an attacker with administrative privileges inside a guest virtual machine to breach the isolation boundary and execute arbitrary code on the underlying host operating system.
According to security advisory VMSA-2026-0007, released on September 3, 2026, the most severe of the two flaws is CVE-2026-59346. This critical integer-overflow vulnerability exists within the VMXNET3 virtual network adapter and carries a CVSSv3 score of 9.3. A second vulnerability, CVE-2026-59347, is a stack-based buffer overflow located in the Host-Guest File System (HGFS), which has been assigned a CVSSv3 score of 8.1.
The Risk of VM Escape
Desktop hypervisors such as VMware Workstation and Fusion are fundamental tools for security researchers and software developers. These professionals rely on these platforms to create sandboxed environments where untrusted code or live malware can be detonated and analyzed without risking the primary system. A "VM-escape" represents one of the most severe failures in virtualization security, as it effectively collapses the wall between the isolated guest and the host.
Industry Implications
These vulnerabilities are particularly dangerous because they only require guest administrative privileges to exploit. In many malware analysis scenarios, the sample being studied is intentionally granted administrative rights to observe its full behavior, or the malware itself is designed to escalate privileges immediately upon execution.
When the security boundary is breached, the host workstation—and by extension, the internal network it is connected to—becomes vulnerable. A detonated malware sample could pivot from the virtual environment to the host, allowing an attacker to steal sensitive data, install persistent backdoors, or move laterally through a corporate infrastructure.
Remediation and Next Steps
Broadcom has confirmed that the vulnerabilities affect VMware Workstation versions 25H2 and 26H1 across all supported host operating systems, as well as VMware Fusion versions 25H2 and 26H1 on macOS.
To remediate these risks, Broadcom has released version 26H1u1. Users are urged to update their installations immediately, as the company stated that no configuration workarounds exist to mitigate these flaws. Administrators should prioritize the update of any machines used for malware analysis or the execution of untrusted third-party software.