Executive Summary
Broadcom patched two critical vulnerabilities in VMware Workstation and Fusion in September 2026, including CVE-2026-59346 (CVSS 9.3), an integer overflow flaw allowing local attackers with elevated VM privileges to execute arbitrary code on the host system. The second vulnerability, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow in HGFS that enables code execution as the VMX process. Both flaws affect versions 25H2 and 26H1, requiring administrative access within a guest VM for exploitation, though such privileges can be obtained through separate compromise vectors like phishing or weak configurations.
This incident highlights the continued targeting of VMware infrastructure by threat actors, following recent active exploitation of vCenter vulnerabilities by suspected China-nexus APT groups that compromised 361 unique victims across 47 countries within days of public disclosure.
Why This Matters Now
VMware virtualization environments remain prime targets for sophisticated threat actors seeking to escape guest VMs and compromise host infrastructure, with recent China-nexus APT campaigns demonstrating rapid weaponization of disclosed vulnerabilities within days of public release.
Attack Path Analysis
Attackers exploit CVE-2026-59346 and CVE-2026-59347 in VMware Workstation/Fusion to achieve VM-to-host escape after gaining local administrative privileges through phishing or weak configurations. The integer overflow and buffer overflow vulnerabilities allow code execution on the hypervisor host, enabling lateral movement to other VMs and infrastructure. Command and control is established through host-level access, followed by exfiltration of sensitive data from compromised virtual environments and potential ransomware deployment for business disruption.
Kill Chain Progression
Initial Compromise
Description
Attacker gains local administrative privileges on virtual machine through phishing campaigns or exploitation of weak user configurations, positioning for hypervisor escape
Related CVEs
CVE-2024-38812
CVSS 9.8An integer overflow vulnerability in VMware Workstation and Fusion VMXNET3 network adapter allows local attackers with administrative privileges on a VM to execute arbitrary code on the host system.
Affected Products:
VMware Workstation Pro – 17.x
VMware Workstation Player – 17.x
VMware Fusion – 13.x
Exploit Status:
no public exploitCVE-2024-38813
CVSS 9.8A stack-based buffer overflow vulnerability in VMware HGFS (Host Guest File System) allows local attackers with administrative privileges on a VM to execute code as the VMX process on the host.
Affected Products:
VMware Workstation Pro – 17.x
VMware Workstation Player – 17.x
VMware Fusion – 13.x
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Escape to Host
Exploitation for Client Execution
Process Injection
Exploit Public-Facing Application
Valid Accounts: Local Accounts
Exploitation of Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Updates and Patches
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.14
DORA – ICT Third-party Risk
Control ID: Article 11
CISA ZTMM 2.0 – Application Workload and Computing Resources
Control ID: Pillar 4
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Critical VMware vulnerabilities enable privilege escalation attacks against virtualization infrastructure, requiring immediate patching of Workstation and Fusion platforms to prevent host compromise.
Computer Software/Engineering
Integer overflow and buffer overflow flaws in VMware products threaten development environments, enabling malicious code execution from guest to host systems.
Financial Services
VMware privilege escalation vulnerabilities pose severe risks to financial virtualization infrastructure, potentially compromising regulatory compliance and sensitive transaction processing systems.
Health Care / Life Sciences
Critical VMware flaws threaten healthcare virtualization environments, risking HIPAA compliance violations and patient data exposure through host system compromise attacks.
Sources
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Codehttps://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.htmlVerified
- VMware Workstation and Fusion Security Updates (VMSA-2024-0013)https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25308Verified
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Codehttps://thehackernews.com/2024/09/critical-vmware-workstation-and-fusion.htmlVerified
- CVE-2024-38812 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-38812Verified
- CVE-2024-38813 Detail - NVDhttps://nvd.nist.gov/vuln/detail/CVE-2024-38813Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF would likely constrain this VMware hypervisor escape attack by limiting lateral movement between virtualized workloads and controlling egress paths. The segmentation controls could reduce the blast radius from hypervisor compromise across the virtualized infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls may have constrained the attacker's ability to gain broad administrative privileges within the virtualized environment, potentially limiting the scope of initial access.
Control: Zero Trust Segmentation
Mitigation: Workload isolation policies may have limited the hypervisor's exposure to guest system processes, potentially constraining the attacker's ability to execute host-level code through guest exploitation.
Control: East-West Traffic Security
Mitigation: Microsegmentation controls would likely constrain lateral movement between virtual machines and infrastructure components, reducing the attacker's ability to reach additional systems from the compromised hypervisor host.
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls may have detected and constrained unauthorized communication patterns from the hypervisor host, potentially limiting the attacker's ability to establish persistent external connections.
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering and data loss prevention controls would likely constrain the attacker's ability to extract large volumes of sensitive data from compromised virtual machines and host systems.
Remaining virtualized assets may face reduced but still significant ransomware deployment risk, with potential impact scope limited to workloads within compromised network segments.
Impact at a Glance
Affected Business Functions
- Virtual Machine Infrastructure
- Development and Testing Environments
- Desktop Virtualization
- IT Operations
Estimated downtime: 1 days
Estimated loss: N/A
Potential exposure of host system data and virtual machine contents for organizations using affected VMware Workstation and Fusion products. Risk primarily affects development environments and virtualized desktop infrastructure where administrative access could lead to host system compromise.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to contain VM-to-host breakout attempts and limit blast radius of hypervisor compromise
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized outbound traffic from compromised virtual infrastructure
- • Enable East-West Traffic Security monitoring to identify anomalous lateral movement between VMs and host systems
- • Establish Multicloud Visibility & Control for centralized policy enforcement and detection of suspicious automation targeting virtualized environments
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal VM behavior and alert on hypervisor escape indicators



