Skip to content
THREATWIRE

News

VMware VMXNET3 guest-to-host overflow is CVE-2026-59346

VMSA-2026-0007 rates CVE-2026-59346 CVSS 9.3: a guest administrator with a VMXNET3 adapter on Workstation or Fusion 25H2/26H1 may execute code on the host. Fixed in 26H1u1. A public PoC demonstrates a host crash. Not in CISA KEV. CVE-2026-59347 is a separate HGFS issue in the same advisory.

Critical

Published 7 Oct 2026

PoC link

On this page

What happened

On 3 September 2026 Broadcom published VMSA-2026-0007 for VMware Workstation and Fusion. CVE-2026-59346 is an integer-overflow issue Broadcom rates Critical at CVSS 3.1 9.3 with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (CWE-190). The known attack vector is a malicious actor with local administrative privileges inside a guest that uses a VMXNET3 virtual network adapter, who may execute code on the host. The same advisory also lists CVE-2026-59347, an HGFS stack buffer overflow scored 8.1; that id is context only in this article.

Who is affected

Operators of VMware Workstation or Fusion on versions 25H2 or 26H1 are in the response matrix. Guests need a VMXNET3 adapter for the published attack path. Broadcom lists no workaround. Cloud ESXi deployments are outside the products named in this VMSA row; desktop Workstation and Fusion on any host OS (Fusion on macOS) are the impacted products in the matrix.

What is confirmed

VMSA-2026-0007 confirms the guest-admin-to-host code-execution impact for CVE-2026-59346 and the fixed version 26H1u1 for both Workstation and Fusion. Broadcom credits independent reporters including Stan S working with Trend Micro Zero Day Initiative (ZDI-26-647). NVD received the CVE on 7 October 2026. GHSA-88p7-h25r-m6vw carries the 9.3 score. CISA has not listed the CVE in KEV; SSVC exploitation is none.

GitHub user 0xCyberstan published a public repository for this CVE. The README states the PoC is a Linux guest kernel module that triggers a 32-bit wrap in the host VMXNET3 TSO segmentation allocation path and claims a host vmware-vmx crash (SIGSEGV), explicitly saying it does not attempt code execution. The author’s blog write-up matches the same CVE and VMSA. ThreatWire did not run the project. Availability is therefore PoC.

What is not confirmed

Exploitation in the wild is not confirmed by Broadcom or CISA. The public PoC’s claimed result is a host process crash, not a demonstrated full arbitrary-code-execution chain; vendor impact remains host code execution. ThreatWire did not verify the module beyond public metadata and README prose. Posts that imply unauthenticated remote internet exploitation ignore the local guest-administrator and VMXNET3 preconditions.

What to do

Upgrade VMware Workstation and Fusion to 26H1u1 from Broadcom downloads. Until then, treat untrusted guests with VMXNET3 and local admin rights as able to attack the host. After upgrading, confirm the installed version matches 26H1u1 release notes.

Sources: VMSA-2026-0007, NVD and CVE.org for CVE-2026-59346, GHSA-88p7-h25r-m6vw, and the public PoC repository metadata.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/vmware-vmxnet3-guest-to-host-is-cve-2026-59346

More articles