CVE-2026-59346 Overview
CVE-2026-59346 is an integer-overflow vulnerability [CWE-190] affecting VMware Workstation and VMware Fusion. The flaw resides in the VMXNET3 virtual network adapter. An attacker with local administrative privileges inside a guest virtual machine can trigger the overflow to execute code on the underlying host operating system. This represents a virtual machine escape, breaking the isolation boundary that hypervisors are designed to enforce.
Critical Impact
Successful exploitation enables guest-to-host code execution, allowing an attacker who controls a VM to compromise the host and potentially pivot to other guests.
Affected Products
- VMware Workstation versions 25H2 and 26H1 (fixed in 26H1u1)
- VMware Fusion versions 25H2 and 26H1 (fixed in 26H1u1)
- Virtual machines configured with the VMXNET3 virtual network adapter
Discovery Timeline
- 2026-10-07 - CVE-2026-59346 published to the National Vulnerability Database (NVD)
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-59346
Vulnerability Analysis
The vulnerability is an integer overflow in the VMXNET3 paravirtualized network adapter emulation code. VMXNET3 is a high-performance virtual NIC used by VMware Workstation and Fusion to accelerate guest network throughput. The adapter is implemented inside the hypervisor process on the host, so any memory-safety flaw in its parsing logic executes in the host context.
An attacker with administrative rights inside the guest can craft network descriptors or buffer size values that overflow an internal integer calculation. The overflow produces an undersized allocation or an out-of-bounds access during subsequent memory operations. The resulting memory corruption is leveraged for arbitrary code execution on the host.
Because the attack originates in the guest and lands on the host, the CVSS scope is marked as changed. Confidentiality, integrity, and availability of the host and all co-resident guests are at risk.
Root Cause
The root cause is improper validation of size or length fields during VMXNET3 packet or descriptor processing. An arithmetic operation on attacker-controlled values wraps around the maximum representable integer, producing a smaller-than-expected result. Downstream code treats the wrapped value as valid, leading to buffer boundary violations in the host process memory.
Attack Vector
Exploitation requires local administrative access inside the guest virtual machine. The attacker interacts with the VMXNET3 adapter from within the guest kernel or driver to deliver crafted inputs. No host-side user interaction is required. The attack vector is local to the hypervisor from the guest perspective, but the impact crosses the virtualization boundary.
Technical details on the specific overflow site are limited in the public advisory. Refer to the Broadcom Security Advisory #38288 for vendor-published information.
Detection Methods for CVE-2026-59346
Indicators of Compromise
- Unexpected crashes or restarts of the vmware-vmx host process coinciding with guest activity
- Host-level process spawns originating from the VMware hypervisor process after guest network driver activity
- Anomalous memory allocation patterns or segmentation faults logged by the host operating system tied to VMware binaries
Detection Strategies
- Monitor host endpoints running VMware Workstation or Fusion for crashes of vmware-vmx processes with abnormal exit codes
- Correlate guest-side kernel driver activity touching VMXNET3 with host process anomalies using endpoint telemetry
- Inventory virtual machines using the VMXNET3 adapter and prioritize those running untrusted workloads
Monitoring Recommendations
- Enable host-level process creation auditing on systems running Workstation or Fusion
- Alert on child processes of vmware-vmx that are not part of the normal hypervisor lifecycle
- Track VMware Workstation and Fusion versions across the fleet and flag installations at 25H2 or 26H1
How to Mitigate CVE-2026-59346
Immediate Actions Required
- Upgrade VMware Workstation and VMware Fusion to version 26H1u1 or later
- Restrict administrative access inside guest VMs that handle untrusted code or data
- Audit all hosts running affected Workstation or Fusion versions and prioritize patching those exposing shared or untrusted VMs
Patch Information
Broadcom has released fixed versions in the 26H1u1 release line for both VMware Workstation and VMware Fusion. Apply the vendor-supplied update as documented in the Broadcom Security Advisory #38288. Reboot guest and host systems as required after installation.
Workarounds
- Where patching is not immediately possible, replace the VMXNET3 adapter with an alternative virtual NIC such as E1000e on affected VMs
- Remove local administrative privileges from untrusted users inside guest virtual machines
- Isolate affected hosts from sensitive networks until the update is applied
# Example: identify VMs configured with VMXNET3 by inspecting .vmx files
grep -l 'ethernet0.virtualDev = "vmxnet3"' /path/to/vms/**/*.vmx
# Mitigation: edit the VM .vmx file to use a different adapter
# ethernet0.virtualDev = "e1000e"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.