CVE-2026-22715: VMware Fusion
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
VMWare Workstation and Fusion contain a logic flaw in the management of network packets. Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's. Resolution: To remediate CVE-2026-22715 please upgrade to VMware Workstation or Fusion Version 25H2U1
Affected products
- VMware Fusion: from 13.0, before 25H2U1 (fixed in 25H2U1)
- VMware Workstation: from 17.0, before 25H2U1 (fixed in 25H2U1)
Published 2026-02-26. Last modified 2026-06-17.