CVE-2026-22715: VMware Fusion

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

VMWare Workstation and Fusion contain a logic flaw in the management of network packets.  Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's.  Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 25H2U1

Affected products

  • VMware Fusion: from 13.0, before 25H2U1 (fixed in 25H2U1)
  • VMware Workstation: from 17.0, before 25H2U1 (fixed in 25H2U1)

Published 2026-02-26. Last modified 2026-06-17.