Affected Systems
VMware Workstation and VMware Fusion versions 25H2 and 26H1. Affects systems using VMXNET3 virtual network adapter (CVE-2026-59346) and HGFS feature (CVE-2026-59347). Both products patched in version 26H1u1.
Exploitation Status
No evidence of active exploitation in the wild. Requires local administrative privileges on the guest VM as a prerequisite. No public PoC available at time of disclosure.
Business Impact
Attackers with admin access inside a VM can break out and execute code on the underlying host system. This enables lateral movement from compromised guest VMs to the hypervisor host, potentially affecting all VMs on that host. Critical for environments where VMs are managed by third parties or untrusted users. Requires prior compromise of guest VM admin credentials (via phishing, weak configs, or other vulnerabilities).
Urgency
🟠Within 24 hours
Recommended Actions
- Update VMware Workstation to version 26H1u1 or later immediately on all affected systems
- Update VMware Fusion to version 26H1u1 or later immediately on all affected macOS hosts
- Audit guest VM administrative access controls and review logs for suspicious privilege escalation or unusual VMX process activity
- Implement least-privilege policies for VM administrators and restrict VMXNET3 adapter use where not operationally required
- Monitor VMware security advisories closely given recent active exploitation of other VMware products (CVE-2026-59309, CVE-2026-59310)
