Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Executive Summary

Broadcom released security updates for two VMware Workstation and Fusion vulnerabilities, including a critical integer‑overflow flaw (CVE-2026-59346, CVSS 9.3). The flaw allows a local attacker with elevated privileges to execute arbitrary code on the host system.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-05T16:05:08+00:00 - Category: vulnerabilities

Original Description: Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

"Better than a thousand hollow words, is one word that brings peace."

— Buddha
Source: The Hacker News