A public proof-of-concept (PoC) exploit has been released for CVE-2026-59346, a critical integer overflow flaw in VMware Workstation and Fusion that could enable a privileged attacker inside a virtual machine to execute code on the underlying host.
Broadcom has assigned this vulnerability a CVSS v3.1 score of 9.3 and has addressed it in VMware Workstation and Fusion version 26H1u1.
The vulnerability specifically affects the VMXNET3 virtual network adapter’s TCP Segmentation Offload (TSO) processing within the vmware-vmx process on the host.
Trend Micro’s Zero Day Initiative (ZDI), which tracks the issue as ZDI-26-647, notes that exploitation requires the attacker first to gain the ability to execute high-privileged code in the guest operating system.
VMXNET3 is VMware’s paravirtualized network interface card (NIC) used by modern virtual machines. When a guest virtual machine transmits a large TCP packet using TSO, VMware’s host-side backend divides the packet into smaller segments before transmission.
The newly released PoC targets a 32-bit multiplication used to calculate the allocation size for these segments. The vulnerable routine multiplies the number of segments by each segment’s size. If the result exceeds the 32-bit integer limit, it wraps around, causing VMware to allocate a much smaller memory buffer than necessary.
However, the subsequent segmentation routine continues writing based on the original, untruncated values, creating an out-of-bounds write in the host’s vmware-vmx process. This means a guest-controlled packet could corrupt memory beyond the allocated heap buffer.
This issue is particularly significant as it follows CVE-2025-41236, an earlier VMXNET3 TSO flaw. According to the PoC repository, the previous patch added checks for the maximum segment size and related fields but did not validate the multiplication used to calculate the final allocation size. As a result, individually valid values could still produce an overflowing product.
Security researcher Stan S has published a Linux guest kernel-module PoC that writes crafted descriptors directly into the VMXNET3 transmit ring.
This module bypasses normal guest-driver validation and triggers processing through the virtual NIC’s memory-mapped I/O doorbell. The public code aims to demonstrate the memory-safety failure.
It causes the host-side vmware-vmx process to crash with a segmentation fault. When the vmware-vmx process terminates, the affected guest VM powers off. The repository explicitly states that the released PoC does not attempt to execute code.
Nevertheless, Broadcom’s advisory warns that a malicious actor with local administrative privileges in a VM configured with a VMXNET3 adapter could exploit CVE-2026-59346 to execute code on the host.
This makes the vulnerability a significant guest-to-host escape risk, especially in environments where untrusted or semi-trusted workloads run on desktop virtualization platforms.
Broadcom lists VMware Workstation versions 25H2 and 26H1, as well as VMware Fusion versions 25H2 and 26H1, as affected. VMware Workstation and Fusion version 26H1u1 contain the fix; Broadcom has not provided a workaround.
Administrators should prioritize upgrading to version 26H1u1 or later, especially when users have administrative access inside guest VMs.
Organizations should also review whether VMXNET3 is necessary for sensitive desktop virtualization workloads and, where possible, restrict guest administrative privileges. ZDI published its advisory on September 9, 2026, after the vulnerability was reported to the vendor on August 26 under coordinated disclosure.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…