SB2026090363 - Multiple vulnerabilities in VMware Workstation and Fusion
Published: September 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Integer overflow (CVE-ID: CVE-2026-59346)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
The vulnerability allows a remote user to execute code on the host.
The vulnerability exists due to integer overflow in the VMXNET3 virtual network adapter when handling VMXNET3 operations on a virtual machine. A remote user with administrative privileges on the guest can execute arbitrary code on the host.
Exploitation requires a virtual machine with a VMXNET3 virtual network adapter.
2) Stack-based buffer overflow (CVE-ID: CVE-2026-59347)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 5 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
The vulnerability allows a remote user to execute code as the virtual machine's VMX process running on the host.
The vulnerability exists due to stack-based buffer overflow in HGFS when handling HGFS operations from a virtual machine. A remote user with administrative privileges on the guest can execute arbitrary code as the virtual machine's VMX process running on the host.
Remediation
Install update from vendor's website.