Stack-Based Buffer Overflow Vulnerability in VMware Workstation and Fusion
CVE-2026-59347

8.1HIGH

Key Information:

Vendor

Vmware

Vendor
CVE Published:
7 October 2026

What is CVE-2026-59347?

A stack-based buffer overflow vulnerability exists in VMware Workstation and Fusion due to improper handling of HGFS. This flaw could potentially allow a malicious actor with local administrative privileges on a virtual machine to exploit the vulnerability, leading to the execution of arbitrary code in the virtual machine's VMX process operating on the host system. Proper updates and security patches are necessary to mitigate this risk and protect your systems.

Affected Version(s)

VMware Fusion macOS 25H2 <= 26H1

VMware Workstation 25H2 <= 26H1

VMware Fusion macOS 26H1u1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.