Skip to content
THREATWIRE

CVE

CriticalPoC Available

CVE-2026-59346

VMware Workstation/Fusion VMXNET3 integer overflow guest-to-host

VMSA-2026-0007: integer overflow (CWE-190) in Workstation and Fusion. A local administrator on a guest with a VMXNET3 adapter may execute code on the host. CVSS 3.1 9.3. Affects 25H2 and 26H1; fixed in 26H1u1. Public PoC exists. Not in CISA KEV.

CVSS
9.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Class
RCE
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
VMware
Products
VMware Workstation, VMware Fusion
Affected
VMware Workstation 25H2 and 26H1; VMware Fusion 25H2 and 26H1 (macOS), per VMSA-2026-0007. Exploitation requires a VMXNET3 virtual network adapter and local administrative privileges inside the guest.
Fixed
26H1u1 for Workstation and Fusion, per VMSA-2026-0007. No workaround listed.
Published
7 Oct 2026
Updated
7 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-59346 is an integer-overflow vulnerability in VMware Workstation and VMware Fusion, disclosed in Broadcom advisory VMSA-2026-0007 (issue date 3 September 2026). VMware scores CVSS 3.1 9.3 with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and assigns CWE-190. The known attack vector is a malicious actor with local administrative privileges on a virtual machine that uses a VMXNET3 virtual network adapter, who may exploit the issue to execute code on the host. Affected product versions are Workstation and Fusion 25H2 and 26H1; the fixed version is 26H1u1. Broadcom lists no workaround. The advisory also covers a separate HGFS stack buffer overflow, CVE-2026-59347 (CVSS 8.1), which is not recorded as an extra ThreatWire card here.

Broadcom thanks h4urek with secsys lab, Y² (@cameudis), and Stan S working with Trend Micro Zero Day Initiative for independent reports. NVD published the CVE record on 7 October 2026. GitHub advisory GHSA-88p7-h25r-m6vw mirrors the 9.3 score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to none.

GitHub user 0xCyberstan published a public repository for CVE-2026-59346. The README describes a Linux guest kernel module that crafts VMXNET3 TSO descriptors to trigger a 32-bit allocation-size wrap in the host vmware-vmx path and claims a host-side crash (SIGSEGV), not a complete code-execution exploit. The author’s write-up aligns with the ZDI-26-647 / VMSA reporting chain. ThreatWire did not run the project. Availability is therefore PoC. This record does not reprint descriptors, module parameters, or payloads.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-59346