Close Menu
NCIJ Network NCIJ Network
    What's Hot

    My Brief Summer Fling With Siri AI

    September 6, 2026

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026

    600 BTC Mined in 2010 Moves After 16 Years of Dormancy

    September 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • My Brief Summer Fling With Siri AI
    • Attackers conceal phishing lures using invisible Unicode characters
    • 600 BTC Mined in 2010 Moves After 16 Years of Dormancy
    • US envoys meet Putin: What’s behind latest diplomacy on Russia-Ukraine war? | Russia-Ukraine war News
    • Trump Administration Again Asks Supreme Court to Allow Mail Voting Restrictions
    • Competitive Pokémon is on phones now, but you still need a Switch to become a champion
    • Solana ETF inflows fall 97% as CME net shorts shrink
    • Some joints may be primed for rheumatoid arthritis before birth
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 5, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 05, 2026Vulnerability / Server Security

    Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.

    The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.

    “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host,” Broadcom said in an alert.

    The tech giant credited @h4urek, @cameudis, and Stan S for discovering the issue.

    Also patched by Broadcom is a stack-based buffer-overflow vulnerability in HGFS (CVE-2026-59347, CVSS score: 8.1), which can be exploited by a bad actor with local administrative privileges on a virtual machine to execute code as the virtual machine’s VMX process running on the host.

    Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab have been acknowledged for reporting the flaw.

    Cybersecurity

    In both cases, successful exploitation hinges on an attacker already possessing local administrative privileges, although it’s worth noting that they can be obtained through a separate compromise through phishing or exploiting weak user configurations.

    The two vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. Broadcom said there are no workarounds that address the two vulnerabilities, adding that they have been patched in VMware Workstation 26H1u1 and VMware Fusion 26H1u1.

    Although there is no evidence that the security flaws have been exploited in the wild, vulnerabilities in VMware products have been an attack magnet.

    As recently as last month, threat actors were observed actively exploiting two shortcomings in VMware vCenter, namely CVE-2026-59309 and CVE-2026-59310, with the latter suspected to be weaponized by a China-nexus advanced persistent threat (APT) actor.

    The activity, which started five calendar days after public disclosure of the flaw, is estimated to have breached 361 unique victim IP addresses across 47 countries. Most of the infections were concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).

    admins Code critical Execute Flaw fusion Host lets VMware Workstation
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers conceal phishing lures using invisible Unicode characters

    AI can now control fusion plasma faster than humans can react

    Green Party deputy leader Mothin Ali linked to property lets in Leeds

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    DAOs are forcing crypto protocols to choose between code and emergency brakes

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    My Brief Summer Fling With Siri AI

    September 6, 2026

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026

    600 BTC Mined in 2010 Moves After 16 Years of Dormancy

    September 6, 2026

    US envoys meet Putin: What’s behind latest diplomacy on Russia-Ukraine war? | Russia-Ukraine war News

    September 6, 2026
    Latest Posts

    Quantum computing nears commercial breakthrough, IBM CEO says

    August 1, 2026

    Amgen says cloud data breach exposed patient health, proprietary info

    August 1, 2026

    Snapchat joins other platforms in the fight against ‘AI slop’

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    My Brief Summer Fling With Siri AI

    September 6, 2026

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026

    600 BTC Mined in 2010 Moves After 16 Years of Dormancy

    September 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.