Broadcom has patched two critical flaws in VMware Workstation and Fusion that let an attacker already inside a virtual machine break out and run code on the physical host, the exact boundary virtualization exists to enforce.

CVE-2026-59346, an integer-overflow bug rated 9.3 on the CVSS scale, allows arbitrary code execution on the host machine. CVE-2026-59347, a stack-based buffer overflow in the products’ shared-folder service rated 8.1, lets an attacker run code as the VMX process. Both affect Workstation and Fusion versions 25H2 and 26H1, and both require the attacker to already hold local administrative privileges inside the guest VM, a bar that secondary compromise or a malicious insider can clear. Broadcom’s advisory credits researchers including Tencent’s Xuanwu Lab and lists no available workaround: the only fix is the update to Workstation 26H1u1 or Fusion 26H1u1.

The original insight here is about where this risk actually concentrates. Desktop virtualization tools like Workstation and Fusion are common in exactly the environments least likely to run hardened, monitored infrastructure: developer laptops, malware analysis sandboxes, and contractor machines running client VMs side by side. A host-escape bug in that setting does not just threaten one VM, it threatens whatever else lives on that same laptop, including corporate credentials and other clients’ environments. Security teams should treat Workstation and Fusion updates on developer and analyst endpoints with the same urgency as a server-side patch, not the lower priority desktop software usually gets, and confirm no one is still running a VM configured with local admin rights inside the guest as a convenience.

Source: Broadcom. Related: SonicWall Patches Its Second SMA Zero-Day Pair and Ordinary Git Access Just Became Root Access.