VMware Workstation and Fusion Flaw Allows Host Code Execution

Broadcom patches critical integer-overflow vulnerability in VMware Workstation and Fusion, potentially exposing users to arbitrary code execution attacks.

Bottom line: Security teams must prioritize patching VMware Workstation and Fusion immediately to prevent potential host code execution attacks.

What's happening: Broadcom has released security updates for VMware Workstation (CVE-2026-59346, CVSS score: 9.3) and Fusion, which could allow an attacker to execute arbitrary code on the host system under specific conditions.

What to do: Security teams should apply the patches as soon as possible, and consider implementing additional security controls, such as network segmentation and regular system monitoring, to mitigate potential risks.

Source: The Hacker News