DEV Community

Cover image for Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Broadcom Patches Critical VM-Escape Flaws in VMware Workstation and Fusion

Summary

Broadcom patched two critical VM-escape vulnerabilities in VMware Workstation and Fusion (CVE-2026-59346 and CVE-2026-59347) that allow attackers with guest admin privileges to execute code on the host system.

Take Action:

If you use VMware Workstation or Fusion (versions 25H2 or 26H1), update to 26H1u1 ASAP. Tthere is no workaround or setting that protects you from these flaws. Prioritize the machines that run untrusted code, malware analysis as well as any third party hosting, since an attacker inside a VM can break out and take over your host and from there reach your network.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)