CVE-2026-59346: critical vulnerability in VMware Workstation
VMware Workstation and Fusion VMXNET3 integer-overflow vulnerability
Published
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.3%
from disclosure to weapon0 days
Published on NVDOct 7
1st PoCSep 15
exploitation probability
0.3%top 84% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host.
Affected versions:
- VMware Workstation: 25H2, 26H1 (fixed in 26H1u1)
- VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
public PoCs found — 1
githubgithub.com/0xCyberstan/CVE-2026-59346-POC★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — VMware Workstation
In the same product, most dangerous first.