CVE-2026-59346: VMware Fusion

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

Affected products

  • VMware VMware Fusion: from 25H2, up to and including 26H1
  • VMware VMware Workstation: from 25H2, up to and including 26H1

Published 2026-10-07. Last modified 2026-10-07.