CVE-2026-59347 PUBLISHED

VMware Workstation and Fusion HGFS stack-based buffer-overflow vulnerability

Assigner: vmware
Reserved: 04.07.2026 Published: 07.10.2026 Updated: 07.10.2026

VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor VMware
Product VMware Workstation
Versions Default: unaffected
  • affected from 25H2 to 26H1 (incl.)
  • Version 26H1u1 is unaffected
Vendor VMware
Product VMware Fusion
Versions Default: unaffected
  • affected from 25H2 to 26H1 (incl.)
  • Version 26H1u1 is unaffected

References

Problem Types

  • CWE-121 Stack-based Buffer Overflow CWE

Impacts

  • A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.