CVE-2026-41702: VMware Fusion
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.
Affected products
- VMware Fusion: before 26h1 (fixed in 26h1)
Published 2026-05-15. Last modified 2026-06-17.