CODERED VTA

Broadcom Patches Integer Overflow and Buffer Overflow Flaws in VMware Workstation and Fusion

Medium
Programmer coding at night
Photo by Nubelson Fernandes on Unsplash

Broadcom has published security advisory VMSA-2026-0007, addressing two memory-safety vulnerabilities in its desktop virtualisation line. The flaws, tracked as CVE-2026-59346 and CVE-2026-59347, are described by the vendor as an integer-overflow issue and a buffer-overflow issue. VMware Workstation and VMware Fusion for macOS are affected in all builds prior to 26H1u1, and fixed releases are already available. Canada's Cyber Centre mirrored the disclosure on 7 October 2026 under advisory AV26-1008. Developer, QA and malware-analysis workstations running these local hypervisors sit squarely inside the affected scope.

Beyond those two weakness classes, the vendor has not published exploitation details, and no proof-of-concept code, attack chain or affected component has been made public. Integer-overflow and buffer-overflow defects are memory-corruption classes, which in general carry the potential for unexpected code execution or process crashes, but Broadcom has not stated what an attacker would gain here. No CVSS score accompanies the Cyber Centre bulletin. Until further technical detail is released, the practical signal for defenders is the version boundary itself: builds before 26H1u1 on either product are in scope, and 26H1u1 is the fixed release.

Desktop hypervisors matter because they are often where untrusted code is deliberately run, which puts the host boundary under routine stress. Exploitation pressure today is low: FIRST EPSS scores CVE-2026-59346 at a 0.3 percent probability of exploitation in the next 30 days and CVE-2026-59347 at 0.2 percent. Neither CVE appears in confirmed in-the-wild activity reported with this disclosure. The exposure is therefore latent rather than active, concentrated on unpatched engineering endpoints.

Attack Surface

Endpoint, Endpoint OS

Tactics

Execution, Privilege Escalation, Defense Evasion

Techniques

  • T1068 – Exploitation for Privilege Escalation
  • T1203 – Exploitation for Client Execution
  • T1611 – Escape to Host

SuperPRO's Threat Countermeasures Procedures

  1. Upgrade VMware Workstation to build 26H1u1 or later, the fixed release named in VMSA-2026-0007 for CVE-2026-59346 and CVE-2026-59347.
  2. Upgrade VMware Fusion on macOS to build 26H1u1 or later; all earlier Fusion builds are listed as affected.
  3. Inventory installed hypervisor versions before scheduling: run 'vmware -v' on Windows and Linux hosts, and on macOS read the Fusion version with 'defaults read /Applications/VMware Fusion.app/Contents/Info.plist CFBundleShortVersionString'.
  4. On hosts that cannot be moved to 26H1u1 immediately, suspend or power off untrusted and malware-analysis guests running under VMware Workstation or Fusion, so that no guest code executes against the unpatched hypervisor build in the interim.
  5. Remove unnecessary virtual hardware from exposed VMs, in particular USB controller passthrough, shared folders and 3D acceleration, to reduce the guest-reachable code surface in vmware-vmx until 26H1u1 is deployed.
  6. Prioritise endpoint monitoring on developer, QA and malware-analysis hosts still running VMware Workstation or Fusion builds earlier than 26H1u1, treating repeated crashes or abnormal termination of the virtual machine process as a trigger for investigation until the 26H1u1 upgrade is complete.
  7. Track the Broadcom VMware Cloud Foundation security advisory page for revisions to VMSA-2026-0007, since the advisory currently carries no published exploitation detail or CVSS rating.

Source

Code Red Cyber / VTA – coderedcyber.ai