importantSYS.SOURCE: The Hacker News• 2026-09-05T21:35:08+05:30
Critical Integer-Overflow Vulnerability in VMware Workstation and Fusion Enables Host Code Execution
A critical integer-overflow vulnerability (CVE-2026-59346, CVSS 9.3) and a stack-based buffer-overflow vulnerability (CVE-2026-59347, CVSS 8.1) in VMware Workstation and Fusion allow privileged attackers to execute host code. Both issues were patched in versions 26H1u1, affecting versions 25H2 and 26H1.
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.
The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.
"A
*** END OF TRANSMISSION ***