CVE-2026-22722: VMware Workstation

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

Affected products

  • VMware Workstation: from 17.0, before 25H2u1 (fixed in 25H2u1)

Published 2026-02-26. Last modified 2026-06-17.