CVE-2026-59346
VMware Workstation/Fusion VMXNET3 integer overflow guest-to-host
VMSA-2026-0007: integer overflow (CWE-190) in Workstation and Fusion. A local administrator on a guest with a VMXNET3 adapter may execute code on the host. CVSS 3.1 9.3. Affects 25H2 and 26H1; fixed in 26H1u1. Public PoC exists. Not in CISA KEV.
- CVSS
- 9.3
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Class
- RCE
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- VMware
- Products
- VMware Workstation, VMware Fusion
- Affected
- VMware Workstation 25H2 and 26H1; VMware Fusion 25H2 and 26H1 (macOS), per VMSA-2026-0007. Exploitation requires a VMXNET3 virtual network adapter and local administrative privileges inside the guest.
- Fixed
- 26H1u1 for Workstation and Fusion, per VMSA-2026-0007. No workaround listed.
- CWE
- CWE-190
- Published
- 7 Oct 2026
- Updated
- 7 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-59346 is an integer-overflow vulnerability in VMware Workstation and VMware Fusion, disclosed in Broadcom advisory VMSA-2026-0007 (issue date 3 September 2026). VMware scores CVSS 3.1 9.3 with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and assigns CWE-190. The known attack vector is a malicious actor with local administrative privileges on a virtual machine that uses a VMXNET3 virtual network adapter, who may exploit the issue to execute code on the host. Affected product versions are Workstation and Fusion 25H2 and 26H1; the fixed version is 26H1u1. Broadcom lists no workaround. The advisory also covers a separate HGFS stack buffer overflow, CVE-2026-59347 (CVSS 8.1), which is not recorded as an extra ThreatWire card here.
Broadcom thanks h4urek with secsys lab, Y² (@cameudis), and Stan S working with Trend Micro Zero Day Initiative for independent reports. NVD published the CVE record on 7 October 2026. GitHub advisory GHSA-88p7-h25r-m6vw mirrors the 9.3 score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none.
GitHub user 0xCyberstan published a public repository for CVE-2026-59346. The README describes a Linux guest kernel module that crafts VMXNET3 TSO descriptors to trigger a 32-bit allocation-size wrap in the host vmware-vmx path and claims a host-side crash (SIGSEGV), not a complete code-execution exploit. The author’s write-up aligns with the ZDI-26-647 / VMSA reporting chain. ThreatWire did not run the project. Availability is therefore PoC. This record does not reprint descriptors, module parameters, or payloads.