CVE-2026-59347: VMware Fusion

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

Affected products

  • VMware VMware Fusion: from 25H2, up to and including 26H1
  • VMware VMware Workstation: from 25H2, up to and including 26H1

Published 2026-10-07. Last modified 2026-10-07.