ZeroHour
Story · 1 source · 1 articlefirst updated ()

Broadcom patches critical VMware Workstation and Fusion VM-escape flaws (CVE-2026-59346, CVE-2026-59347); VDDK download removal complicates VMware migrations

What's new: Initial merged summary; no prior summary existed. Timeline: (1) Around 2026-08-25, Broadcom removed public VDDK download pages; ShapeBlue documented VDDK 8 and 9 download errors the same day, with Broadcom support later confirming the removal (reported 2026-09-07, Hacker News - AI). (2) Reported 2026-09-05 (Security Affairs, The Hacker News): Broadcom's VMSA-2026-0007 patched the two…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Broadcom's advisory VMSA-2026-0007 fixes two VMware Workstation and Fusion VM-escape flaws in 25H2/26H1, fixed in 26H1u1 with no workarounds: CVE-2026-59346, an integer overflow in the VMXNET3 TSO segmentation code rated CVSS 9.3 by Broadcom but CVSS 7.5 by…

Broadcom released security advisory VMSA-2026-0007 fixing two vulnerabilities in VMware Workstation and Fusion 25H2 and 26H1 that allow a malicious actor with local administrative privileges inside a VM to execute code on the host. CVE-2026-59346 is an integer overflow in the VMXNET3 virtual network adapter, which ZDI's advisory (ZDI-26-647) further locates in the VMXNET3 TSO segmentation code; per Security Affairs and The Hacker News it lets a guest admin execute host code via the VMXNET3 adapter, while ZDI characterizes it as a local privilege escalation requiring prior execution of high-privileged code on the guest. Sources disagree on severity: Broadcom rates it CVSS 9.3, while ZDI's published advisory lists CVSS 7.5. CVE-2026-59347, rated CVSS 8.1, is a stack-based buffer overflow in HGFS allowing code execution as the host's VMX process. Both flaws are fixed in Workstation 26H1u1 and Fusion 26H1u1, and no workarounds are available. The bugs were reported independently by researchers working with Trend Micro Zero Day Initiative and by Tencent Xuanwu Lab. Neither The Hacker News nor ZDI reports any in-the-wild exploitation of the two flaws. The Hacker News adds related context: VMware vCenter flaws CVE-2026-59309 and CVE-2026-59310 are actively exploited, with 361 unique victim IPs across 47 countries, and the latter is suspected of China-nexus APT use. In a related Broadcom move, a 2026-09-07 report (Hacker News - AI) documents that Broadcom removed the publicly accessible VMware Virtual Disk Development Kit (VDDK) download pages around August 25, 2026, with no deprecation notice; Broadcom support told customers the VDDK is 'no longer available for use or download', and ShapeBlue documented the same day that VDDK 8 and 9 download paths all return errors. The library underpins migration tools including Microsoft Azure Migrate, Red Hat's Migration Toolkit, Nutanix Move, virtv2v and nbdkit; Microsoft has updated Azure Migrate documentation to warn that Broadcom may restrict VDDK access, and no replacement library or official announcement has been published.

  • Broadcom advisory VMSA-2026-0007 fixes CVE-2026-59346 and CVE-2026-59347, affecting VMware Workstation and Fusion 25H2 and 26H1; fixes are in Workstation 26H1u1 and Fusion 26H1u1, with no workarounds available.
  • CVE-2026-59346 is an integer overflow in the VMXNET3 virtual network adapter; ZDI's advisory ZDI-26-647 specifies the vulnerable code as the VMXNET3 TSO segmentation code.
  • Severity discrepancy for CVE-2026-59346: Security Affairs and The Hacker News cite Broadcom's CVSS 9.3, while ZDI's published advisory lists CVSS 7.5.
  • Framing discrepancy for CVE-2026-59346: Broadcom-side reports describe guest admins executing code on the host (VM escape); ZDI characterizes it as local privilege escalation requiring prior high-privileged code execution on the guest.
  • CVE-2026-59347 is a stack-based buffer overflow in HGFS, rated CVSS 8.1, allowing code execution as the host's VMX process.
  • The Workstation/Fusion flaws were reported independently by researchers working with Trend Micro Zero Day Initiative and by Tencent Xuanwu Lab.
  • No in-the-wild exploitation of CVE-2026-59346 or CVE-2026-59347 has been observed (The Hacker News); ZDI's advisory reports no exploitation.
  • Context per The Hacker News: VMware vCenter flaws CVE-2026-59309 and CVE-2026-59310 are actively exploited, hitting 361 unique victim IPs across 47 countries; CVE-2026-59310 is suspected of China-nexus APT use.

Coverage timeline

  1. · 11d ago
    Security Affairs· 65
    Broadcom Patches Critical VMware Workstation and Fusion VM

    Broadcom patched critical VMware Workstation and Fusion VM-escape flaws CVE-2026-59346 (CVSS 9.3) and CVE-2026-59347 (CVSS 8.1); update to 26H1u1.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

NVD description · AI analysis pending
9.88%
  • vmware vcenter server
CVE-2026-59310
Unauthenticated Path Traversal RCE in Broadcom VMware vCenter Server Syslog

CVE-2026-59310 is a directory traversal (CWE-22) vulnerability in the Syslog server component of VMware vCenter Server, rated critical at CVSS 9.8. It can be triggered over the network without authentication or user interaction, allowing a malicious actor with network access to vCenter to achieve arbitrary code execution. An attacker who exploits it gains code execution on the vCenter appliance, and reported campaigns show it has been used to establish persistent remote access and, by a suspected China-nexus actor, to deploy Babuk ransomware. Any organization running an affected version of vCenter Server is exposed, especially where the management interface is reachable from the internet; the available data does not specify affected version ranges. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-08-18, it was reportedly exploited just five days after disclosure, and EPSS estimates a 45.9% probability of exploitation within 30 days (99th percentile).

Do: Upgrade vCenter Server to the patched release identified in Broadcom's advisory (no specific version ranges are provided in this data) and prioritize any vCenter that is internet-facing, in line with CISA KEV and BOD 26-04 requirements for federal agencies. Until patched, restrict access to the vCenter management interface to trusted networks and verify whether the vCenter Syslog server is enabled. Hunt for compromise indicators, including unexplained remote-access persistence and Babuk ransomware artifacts, given the documented China-nexus exploitation.

9.846% KEV ransomware
  • Broadcom (VMware) vCenter Server
largeApproximately 50,000-100,000 internet-exposed vCenter Server instances, with total deployments (including internal-only) likely in the hundreds of thousands
CVE-2026-59346

NVD description · AI analysis pending
PoC
CVE-2026-59347

NVD description · AI analysis pending