Visualização de leitura

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately.

Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround.

The first vulnerability, tracked as CVE-2026-59346 (CVSS score of 9.3), is an integer-overflow vulnerability. The issue resides in the VMXNET3, a virtual network adapter (virtual NIC) designed by VMware for virtual machines.

An attacker with local admin privileges on a virtual machine using a VMXNET3 network adapter could exploit this flaw to run code on the host.

“VMware Workstation and Fusion contain an integer-overflow vulnerability.” reads the advisory. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.”

Researchers h4urek(@h4urek) with secsys lab & Y² (@cameudis) and Stan S, working with TrendAI Zero Day Initiative, independently reported this flaw to the vendor.

The second issue, tracked as CVE-2026-59347 (CVSS score of 8.1), is a stack-based buffer overflow in HGFS component. Host-Guest File System (HGFS) is a VMware feature that lets a virtual machine (guest) access files and directories located on the physical host.

An attacker with local administrator privileges on a virtual machine could exploit this flaw to execute code with the privileges of the VMX process running on the host.

“VMware Workstation and Fusion contain a stack-based buffer-overflow vulnerability in HGFS.” continues the advisory. “A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host.”

Researchers Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab reported the vulnerability to Broadcom.

The vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. Workstation runs on Windows and Linux, while Fusion runs on macOS. VMware fixed both flaws in version 26H1u1.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Broadcom )

Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine.

Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a VM escape flaw in the VMXNET3 virtual network adapter. An attacker with administrator privileges inside a virtual machine could exploit it to execute arbitrary code on the underlying ESXi host.

“VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.3.” reads the advisory. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.”

Broadcom also fixed a critical vCenter authentication bypass, tracked as CVE-2026-59309 (CVSSv3 base score of 9.8), that can be exploited to gain unauthorized access to the targeted system.

“VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.” reads the advisory. “A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.”

The third critical issue fixed by the company is CVE-2026-59310 (CVSSv3 base score of 9.8), a flaw allowing an attacker with network access to execute arbitrary code. 

“VMware vCenter contains a directory traversal vulnerability in the Syslog server. Broadcom has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.”states the advisory.”A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.”

The vendor also patched CVE-2026-41703 (CVSSv3 score of 7.6), a high-severity flaw affecting VMware ESXi, Workstation, and Fusion that could allow an attacker with VM deployment permissions to disclose information or cause a denial-of-service on the host. Another issue, CVE-2026-41709 (CVSSv3 score of 7.6), lets an administrator perform certain actions on ESXi without logging in. Although no active exploitation has been reported, Broadcom urges customers to apply the updates promptly.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, virtual machine)

Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom

Security updates are not just for enterprises with a dedicated security team and a change-management calendar. For consumers and small businesses, they are one of the simplest ways to shut down known attack paths before criminals get a chance to use them.

That matters because attackers love these flaws. because browser bugs, code execution issues, authentication bypasses, and privilege-escalation problems can be turned into a foothold, a data theft opportunity, or a full system compromise if left unpatched.

If you only do one thing after reading a security advisory, make it this: update the affected software promptly, restart when required, and verify the version afterward.

Adobe

Adobe released a large batch of security updates covering ColdFusion, Commerce/Magento Open Source, and Experience Manager. The ColdFusion bulletin alone includes multiple critical flaws that could lead to arbitrary code execution.

The updates and instructions can be found on the pages we linked to.

Chrome

Google patched 15 security flaws in Chrome, including two critical use-after-free bugs in Ozone. The fixes are in Chrome 150.0.7871.124/.125, depending on platform.

You can find an explanation of the version numbering system and step-by-step instructions in our guide to how to update Chrome on every operating system.

Firefox

Mozilla fixed two critical Firefox flaws in Firefox 152.0.6, and it says public exploit code exists for both issues. One affects JavaScript/WebAssembly and the other involves DOM navigation and site isolation, which makes this more than routine housekeeping.

Users should update Firefox to version 152.0.6 as soon as possible. For most users this can simply be done by restarting the browser. If you see the “What’s new” tab, the update is complete.

VMWare

Broadcom released a fix for a critical authentication bypass in VMware Avi Load Balancer, tracked as CVE-2026-47865. The issue could allow a network-accessible attacker to reach the Avi Control Plane, which makes it especially important in environments that expose management services or rely on load balancers at the edge.

Updates and the instructions to apply them can be found in the Security Advisory.

Zoom

Zoom Security Bulletin ZSB-26014 covers a critical issue in Zoom Workplace for Windows, described as improper input validation. The public record identifies the issue as CVE-2026-53412.

For users, the action item is to update Zoom Workplace for Windows to the vendor-fixed release as soon as it is available in your environment. For small businesses, that means updating not just the app on employee laptops, but also any centralized deployment package so the old build doesn’t come right back on the next install cycle.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


April 2026 Dark Web Breach Incident Trend Report

Notes the April 2026 Dark Web Breach Incident Trend Report is compiled from data breach cases posted on the deep web and dark web forums. some information is included in cases where it is difficult to fully verify the factuality of the information due to the nature of the source. Major Issues data breaches and […]
❌