<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code]]></title><description><![CDATA[<p dir="auto">Broadcom has rolled out patches for two security vulnerabilities affecting <strong>VMware Workstation</strong> and <strong>VMware Fusion</strong>, one of which carries a critical severity rating and could allow an attacker to break out of the virtual machine environment.</p>
<p dir="auto">The more serious issue, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59346" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-59346</a></strong> with a CVSS score of <strong>9.3</strong>, is an integer-overflow vulnerability. Exploitation requires an attacker to already hold elevated privileges on the guest operating system. If successfully triggered, the flaw permits arbitrary code execution on the host system—effectively allowing a VM administrator to compromise the underlying machine.</p>
<ul>
<li>The flaw stems from improper handling of integer operations, leading to memory corruption.</li>
<li>Successful exploitation grants code execution in the context of the host process.</li>
<li>No user interaction is required beyond the initial local access.</li>
</ul>
<p dir="auto">Broadcom has not indicated that either vulnerability has been exploited in the wild as of the disclosure date.</p>
<p dir="auto">For administrators running virtualized environments, the patch release underscores the importance of treating guest-level administrative access as a security boundary. Mitigation steps include:</p>
<ul>
<li>Updating <strong>VMware Workstation</strong> and <strong>Fusion</strong> to the latest patched versions immediately.</li>
<li>Restricting administrative access to VMs to trusted personnel only.</li>
<li>Monitoring vendor advisories for additional context on affected build numbers.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team already begun testing the updated builds, or are you holding off until the broader rollout stabilizes?</p>
]]></description><link>https://xploitlk.com/topic/229/critical-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-execute-host-code</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:27:41 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/229.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 Sep 2026 20:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>