Ethical Hacking News
Broadcom has patched two critical vulnerabilities in VMware Workstation and Fusion, providing a timely fix for organizations that use these software applications. The vulnerabilities, CVE-2026-59346 and CVE-2026-59347, allow attackers with local admin privileges to execute code on the host system, making it essential to update to the patched version as soon as possible.
Broadcom has patched two critical vulnerabilities in VMware Workstation and Fusion, two popular virtualization software applications. The first vulnerability, CVE-2026-59346, is an integer-overflow vulnerability in the VMXNET3 virtual network adapter. The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow in the HGFS component. The vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. No workarounds exist for these vulnerabilities, and organizations are advised to update to the patched version. Staying up-to-date with the latest security patches and vulnerability fixes is crucial in preventing and responding to cyber attacks. Other notable security incidents and updates include Google Chromium V8 flaw, Manchester Airports Group hack, and a 12-year-old PostgreSQL vulnerability.
In the ever-evolving landscape of cybersecurity, new vulnerabilities and patches are emerging regularly, leaving organizations and individuals vulnerable to attacks. Recently, Broadcom has patched two critical vulnerabilities in VMware Workstation and Fusion, two popular virtualization software applications used for running virtual machines. This patching serves as a reminder of the ongoing battle against cyber threats and the importance of staying vigilant in the face of emerging security risks.
The first vulnerability, CVE-2026-59346, is an integer-overflow vulnerability in the VMXNET3 virtual network adapter, which is designed by VMware for virtual machines. This vulnerability allows an attacker with local admin privileges on a virtual machine to execute code on the underlying host, providing a potential entry point for malicious actors to compromise the host system. The second vulnerability, CVE-2026-59347, is a stack-based buffer overflow in the HGFS component, which is a VMware feature that enables virtual machines to access files and directories located on the physical host. This vulnerability also allows an attacker with local admin privileges on a virtual machine to execute code with the privileges of the VMX process running on the host.
Researchers from various security firms, including secsys lab, TrendAI Zero Day Initiative, and Tencent Xuanwu Lab, have independently reported these vulnerabilities to the vendors. The vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1, with Workstation running on Windows and Linux, and Fusion running on macOS.
The good news is that Broadcom has patched both vulnerabilities in version 26H1u1, providing a timely fix for organizations that use these software applications. However, the bad news is that no workarounds exist for these vulnerabilities, making it essential for users to update to the patched version as soon as possible.
This incident highlights the importance of staying up-to-date with the latest security patches and vulnerability fixes. It also underscores the need for organizations to implement robust security measures, such as regular vulnerability scanning, patch management, and employee training, to prevent and respond to cyber attacks.
In addition to the VMware vulnerability patching, other notable security incidents and updates include the addition of Google Chromium V8 flaw to the Known Exploited Vulnerabilities catalog by the U.S. CISA, the leak of 8.8 million people's data in a Manchester Airports Group hack, and the discovery of a 12-year-old vulnerability in PostgreSQL that allows server takeover.
As the cyber threat landscape continues to evolve, it is essential for organizations and individuals to remain vigilant and proactive in their security efforts. By staying informed about emerging vulnerabilities and patches, and by implementing robust security measures, we can reduce the risk of cyber attacks and protect our digital assets.
Related Information:
https://www.ethicalhackingnews.com/articles/Malware-and-Vulnerability-Patching-The-Ongoing-Battle-Against-Cyber-Threats-ehn.shtml
https://securityaffairs.com/198465/security/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities.html
https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/
https://nvd.nist.gov/vuln/detail/CVE-2026-59346
https://www.cvedetails.com/cve/CVE-2026-59346/
https://nvd.nist.gov/vuln/detail/CVE-2026-59347
https://www.cvedetails.com/cve/CVE-2026-59347/
Published: Sat Sep 5 01:10:07 2026 by llama3.2 3B Q4_K_M