Technology newsroom
Urgent Alert! Critical Vulnerability in VMware Workstation and Fusion: VM Admins Risk Host Takeover π±
Broadcom has released an urgent patch for a critical vulnerability in VMware Workstation and Fusion that could allow hackers to gain control of the main host machine from within a VM. Users should update immediately for security.
π Key Highlights:
- A critical vulnerability (CVSS 9.3) identified as CVE-2026-59346 has been found in VMware Workstation and Fusion.
- Attackers with administrative privileges in a Guest VM can exploit this vulnerability to run code on the main Host machine, posing a very dangerous situation.
- Broadcom has released a corrective patch. Users should update to version 17.5.3 for Workstation and 13.5.3 for Fusion immediately.
Broadcom, VMware's parent company, has issued a security advisory and released updates to address two vulnerabilities affecting popular software VMware Workstation and Fusion. One of these is a critical severity vulnerability that could allow attackers to execute malicious code on the main host computer.
π¨ Critical Vulnerability (CVE-2026-59346)
The primary vulnerability discovered is CVE-2026-59346, rated with a high severity score of 9.3 (Critical). It is an integer-overflow vulnerability in the Shader functionality. This vulnerability allows attackers with elevated privileges within the Guest OS to exploit this flaw to successfully execute code on the Host OS, a scenario commonly known as "VM Escape."
Another vulnerability addressed concurrently is CVE-2026-59347, rated High (CVSS 7.1). This is a use-after-free vulnerability with a similar impact: it can lead to code execution on the Host machine if the attacker has admin privileges within the VM.
π» Affected Products and Solutions
Users of VMware software on Windows, Linux, and macOS should check and update immediately. Affected products include:
- VMware Workstation Pro / Player version 17.x (resolved in version 17.5.3)
- VMware Fusion Pro / Fusion version 13.x (resolved in version 13.5.3)
Credit for the discovery of this vulnerability goes to the security research team at Ant Group Light-Year Security Lab. This security patch update is therefore crucial for system administrators and developers who use virtualization technology in their work, to prevent the risk of attacks and takeover of their main computers.
π¬ Who among you uses VMware Workstation or Fusion for work or system testing? Have you updated to the latest patch yet?