Broadcom Fixes VMware Workstation and Fusion Escape Vulnerability

Broadcom has addressed CVE-2026-59346, a critical integer overflow in VMware Workstation and VMware Fusion. Rated 9.3 on the CVSS scale, the flaw could allow an attacker with administrative access inside a guest virtual machine to break out of the virtualization boundary and run code on the host. The problem is located in VMware's VMXNET3 virtual network adapter.
Broadcom has issued updates for VMware Workstation and Fusion after identifying CVE-2026-59346, a serious integer overflow rated 9.3 under CVSS. The defect sits in the VMXNET3 virtual network adapter. An attacker with administrative rights inside a guest could cross the virtualization boundary and run code on the host.
The affected releases span the 25H2 and 26H1 lines. Broadcom shipped corrections in Workstation 26H1u1 and Fusion 26H1u1. Because no workaround was offered, applying the vendor's patches is the main way to reduce exposure.
The flaw could matter most to organizations running VMware Workstation or Fusion for development, testing, research, or enterprise virtualization. If exploited, a compromised guest could potentially reach the host, so affected teams may face broader system compromise, data exposure, or service disruption. Patching promptly could reduce that risk, though the practical impact depends on whether attackers already hold administrative rights inside a virtual machine.