CVE-2026-41702: VMware Fusion

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges may exploit this vulnerability to escalate privileges to root on the system where Fusion is installed.

Affected products

  • VMware Fusion: before 26h1 (fixed in 26h1)

Published 2026-05-15. Last modified 2026-06-17.