CVE-2026-59346 PUBLISHED

VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability

Assigner: vmware
Reserved: 04.07.2026 Published: 07.10.2026 Updated: 07.10.2026

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.

Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.3

Product Status

Vendor VMware
Product VMware Workstation
Versions Default: unaffected
  • affected from 25H2 to 26H1 (incl.)
  • Version 26H1u1 is unaffected
Vendor VMware
Product VMware Fusion
Versions Default: unaffected
  • affected from 25H2 to 26H1 (incl.)
  • Version 26H1u1 is unaffected

References

Problem Types

  • CWE-190 Integer Overflow or Wraparound CWE

Impacts

  • A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.