VMware Flaws Can Escape a Guest—26H1u1 Is the Only Fix

Broadcom published a security advisory on September 3 for two VMware Workstation and Fusion vulnerabilities that can carry code execution from an affected virtual machine onto its host. Workstation and Fusion installations on the listed 25H2 or 26H1 release lines must be updated to 26H1u1; Broadcom lists no workaround.
On September 4, CERT-FR’s corresponding notice described Fusion and Workstation versions earlier than 26H1u1 as affected and directed administrators to the vendor bulletin for patches. The more precise product decision comes from Broadcom’s response matrix, which names the affected release lines and the fixed version.
Which Workstation and Fusion installations are affected

The scope is limited to VMware’s desktop hypervisors, not ESXi. Broadcom advisory VMSA-2026-0007 lists VMware Workstation 25H2 and 26H1 with “Any” in the host-platform column, and VMware Fusion 25H2 and 26H1 on macOS. For both products and both vulnerabilities, the fixed version is 26H1u1.
That matrix provides the practical test: identify the installed product, then read the application’s installed release. Workstation or Fusion reporting 25H2 or 26H1 is in the affected set; an installation reporting 26H1u1 has reached the release Broadcom identifies as fixed.
CERT-FR uses the broader wording “versions earlier than 26H1u1,” while Broadcom enumerates 25H2 and 26H1 in its response matrix. Administrators deciding whether a specific installation is covered should use the vendor matrix rather than assume that every historical Workstation or Fusion release has the same support or patch path.
VMXNET3 creates the critical guest-to-host path

CVE-2026-59346 is an integer-overflow vulnerability in Workstation and Fusion. Broadcom assigns it a maximum CVSS v3 base score of 9.3 and says a malicious actor with local administrative privileges inside a virtual machine using a VMXNET3 virtual network adapter may exploit it to execute code on the host.
The prerequisite is important but narrow. The documented path requires both administrative control inside the guest and a VM configured with VMXNET3; merely running Workstation or Fusion does not satisfy the full attack description. Once those conditions are met, however, the flaw can cross the boundary that is supposed to isolate the guest from its host operating system.
VMXNET3 inventory can therefore help administrators prioritize exposed systems, especially hosts running untrusted or heavily delegated guests. It is not a substitute for patch compliance: Broadcom does not recognize changing the adapter, limiting guest privileges or shutting down selected VMs as a workaround for the vulnerable product build.
The HGFS flaw is a separate escape route

CVE-2026-59347 is a stack-based buffer overflow in HGFS, VMware’s host-guest file-system component. Broadcom gives it a maximum CVSS v3 base score of 8.1 and says an actor with local administrative privileges inside a VM may execute code as that virtual machine’s VMX process on the host.
Unlike the first vulnerability, Broadcom’s attack description for CVE-2026-59347 does not specify VMXNET3. An inventory that finds no VMXNET3 adapters may eliminate the stated adapter condition for CVE-2026-59346, but it does not clear an affected Workstation or Fusion installation of the second flaw.
NHS England’s September 3 cyber alert independently lists Workstation and Fusion 25H2 and 26H1 as affected and says upgrading to 26H1u1 remediates both release lines. Because the two attack paths end at the host through different components, VM configuration checks are useful for exposure analysis but cannot replace the product update.
How to verify the remediation
Patch verification should be based on the installed desktop-hypervisor release after deployment, not solely on an update system’s success message. Administrators can query their software inventory or use the product’s version display, then record the result for each Workstation and Fusion endpoint.
- Separate the inventory into VMware Workstation and VMware Fusion installations.
- Record the installed product release and flag every endpoint reporting 25H2 or 26H1.
- Deploy the appropriate Workstation or Fusion 26H1u1 package.
- Restart or relaunch the installed application so the post-update version can be read from the updated product.
- Confirm that the application itself reports 26H1u1 before closing the remediation record; investigate any endpoint that still reports 25H2 or 26H1.
Do not confuse the hypervisor’s release with the guest’s virtual-hardware level, operating-system patch state or VMware Tools version. Those values describe different components and do not prove that the affected Workstation or Fusion installation reached 26H1u1.
The current vendor position is unambiguous: patches are available, both listed vulnerabilities have the same fixed release, and neither has a documented workaround. VMXNET3 identifies the prerequisite for the higher-rated path, but only verification of 26H1u1 establishes that a listed desktop-hypervisor installation has received the vendor’s remediation.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.