Critical VM‑Escape Vulnerabilities Patched in VMware Workstation & Fusion (CVE‑2026‑59346, CVE‑2026‑59347)
What Happened – Broadcom released advisory VMSA‑2026‑0007 fixing two VM‑escape flaws in VMware Workstation and Fusion. CVE‑2026‑59346 (critical, CVSS 9.3) is an integer‑overflow in the VMXNET3 virtual NIC; CVE‑2026‑59347 (high, CVSS 8.1) is a stack‑based buffer overflow in the HGFS file‑sharing component. Both allow a malicious user with local admin rights inside a guest VM to execute code on the underlying host. No work‑arounds exist; customers must upgrade to version 26H1u1 immediately.
Why It Matters for Trust & Control Assurance
- The scenario tests the control objective of isolating guest workloads from the host – a core assurance requirement for continuous monitoring of segregation controls.
- Demonstrating that you have a documented patch‑management process and evidence of timely remediation satisfies multiple frameworks (e.g., NIST CSF 2.0 Protect function) with a single control.
- Leveraging Verisq’s Control‑Mapping capability lets you map these VM‑escape findings to the VCF control “Logical Separation of Environments” and capture audit‑ready evidence of remediation.
Who Is Affected – Enterprises that run VMware Workstation on Windows/Linux or VMware Fusion on macOS, spanning cloud‑infrastructure providers, development labs, and remote‑desktop environments.
Recommended Actions
- Deploy the 26H1u1 update to all affected Workstation and Fusion installations without delay.
- Inventory systems using the VMXNET3 adapter or HGFS feature; document the patch status in your configuration management database (CMDB).
- Update your control‑mapping repository to reflect remediation of the “Virtual Environment Isolation” control and capture the patch‑install logs as evidence.
- Enable host‑level monitoring for anomalous VM‑process activity to detect any attempted exploitation.
Source: SecurityAffairs – Broadcom Patches Critical VMware Workstation and Fusion VM‑Escape Vulnerabilities
Technical Notes –
- CVE‑2026‑59346: Integer overflow in VMXNET3 driver; local admin on guest → code execution on host.
- CVE‑2026‑59347: Stack buffer overflow in HGFS; local admin on guest → code execution as VMX process.
- Affected versions: Workstation 25H2 / 26H1, Fusion 25H2 / 26H1; fixed in 26H1u1. No known work‑arounds.