CVE-2026-59347: VMware Fusion
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
Affected products
- VMware VMware Fusion: from 25H2, up to and including 26H1
- VMware VMware Workstation: from 25H2, up to and including 26H1
Published 2026-10-07. Last modified 2026-10-07.