started · updated
Broadcom patches critical VMware Workstation and Fusion vulnerabilities
Broadcom has released VMware Workstation Pro 26H1u1 to address critical security vulnerabilities that allow for VM-escape attacks. The update patches two significant flaws: CVE-2026-59346, an integer-overflow vulnerability in the VMXNET3 virtual network adapter, and CVE-2026-59347, a stack-based buffer overflow in the Host-Guest File System (HGFS) component.
Both vulnerabilities could allow an attacker with local administrative privileges on a virtual machine to execute code on the underlying host system. There are currently no known workarounds for these issues, making the update essential for users of VMware Workstation and Fusion.
In addition to security patches, the 26H1u1 release introduces automated Secure Boot Platform Key remediation. This feature addresses Microsoft Secure Boot certificate expiration by providing mechanisms to update invalid Platform Keys during guest reboots, supporting both virtual machines without vTPM and those with vTPM enabled.