ZeroHour
Story · 1 source · 1 articlefirst updated ()

Broadcom patches critical VMware Workstation/Fusion flaws CVE-2026-59346 and CVE-2026-59347 as ZDI details the VMXNET3 bug and VDDK downloads vanish

What's new: 2026-09-09 ZDI published ZDI-26-647 disclosing CVE-2026-59346 as a CVSS 7.5 local privilege escalation flaw in VMware Workstation's VMXNET3 TSO segmentation code; no exploitation reported in the advisory.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Broadcom fixed two VMware Workstation and Fusion flaws in 26H1u1: CVE-2026-59346, a VMXNET3 integer overflow rated CVSS 9.3 by Broadcom's advisory but 7.5 by ZDI (ZDI-26-647), and CVE-2026-59347, a CVSS 8.1 HGFS stack buffer overflow; no exploitation…

Broadcom released updates for VMware Workstation and Fusion fixing two flaws that affect versions 25H2 and 26H1, have no workarounds, and are fixed in Workstation 26H1u1 and Fusion 26H1u1. CVE-2026-59346 is an integer overflow in the VMXNET3 virtual network adapter (ZDI locates it in the TSO segmentation code) that lets a malicious actor with local administrative privileges on a guest VM execute code on the host; sources disagree on severity (CVSS 9.3 per The Hacker News vs 7.5 per ZDI-26-647) and on framing (host code execution vs local privilege escalation requiring prior high-privileged code execution on the guest). CVE-2026-59347 (CVSS 8.1) is a stack-based buffer overflow in HGFS allowing code execution as the host's VMX process. No in-the-wild exploitation of either flaw has been observed or reported. As context, The Hacker News notes VMware vCenter flaws CVE-2026-59309 and CVE-2026-59310 are actively exploited - the latter suspected of China-nexus APT use - having recently breached 361 unique victim IPs across 47 countries. In a related ecosystem development, Broadcom removed the publicly accessible VMware Virtual Disk Development Kit (VDDK) download pages around August 25, 2026 with no deprecation notice or explanation; ShapeBlue documented that VDDK 8 and 9 download paths return errors, and Broadcom support told customers the VDDK is 'no longer available for use or download.' Tools depending on it - Microsoft Azure Migrate, Red Hat's Migration Toolkit, Nutanix Move, virtv2v, and nbdkit - are broken or complicated. Microsoft updated Azure Migrate documentation to warn that Broadcom may restrict VDDK access; no replacement library or official announcement has been published.

  • CVE-2026-59346: integer overflow in the VMXNET3 virtual network adapter of VMware Workstation/Fusion (ZDI identifies it in the TSO segmentation code, ZDI-26-647); a guest VM admin can execute code on the host (The Hacker News) or escalate…
  • Severity conflict for CVE-2026-59346: CVSS 9.3 per The Hacker News (Broadcom's advisory) vs CVSS 7.5 per ZDI's ZDI-26-647.
  • CVE-2026-59347 (CVSS 8.1): stack-based buffer overflow in HGFS allowing code execution as the host's VMX process.
  • Both flaws affect VMware Workstation and Fusion 25H2 and 26H1, have no workarounds, and are fixed in Workstation 26H1u1 and Fusion 26H1u1.
  • No in-the-wild exploitation of CVE-2026-59346 or CVE-2026-59347 observed or reported.
  • Context: vCenter flaws CVE-2026-59309 and CVE-2026-59310 are actively exploited; CVE-2026-59310 is suspected of China-nexus APT use; the two recently breached 361 unique victim IPs across 47 countries.
  • Broadcom removed public VDDK download pages around August 25, 2026 without notice or explanation; VDDK 8 and 9 download paths return errors (ShapeBlue); Broadcom support confirmed the VDDK is 'no longer available for use or download.'
  • VDDK-dependent tools affected: Microsoft Azure Migrate, Red Hat Migration Toolkit, Nutanix Move, virtv2v, nbdkit; no replacement library or official announcement has been published.

Coverage timeline

  1. · 11d ago
    The Hacker News· 60
    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    Broadcom patched two VMware Workstation and Fusion flaws, including critical integer overflow CVE-2026-59346 (CVSS 9.3), letting guest admins execute host code; no exploitation seen.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-59309
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

NVD description · AI analysis pending
9.88%
  • vmware vcenter server
CVE-2026-59310
Unauthenticated Path Traversal RCE in Broadcom VMware vCenter Server Syslog

CVE-2026-59310 is a directory traversal (CWE-22) vulnerability in the Syslog server component of VMware vCenter Server, rated critical at CVSS 9.8. It can be triggered over the network without authentication or user interaction, allowing a malicious actor with network access to vCenter to achieve arbitrary code execution. An attacker who exploits it gains code execution on the vCenter appliance, and reported campaigns show it has been used to establish persistent remote access and, by a suspected China-nexus actor, to deploy Babuk ransomware. Any organization running an affected version of vCenter Server is exposed, especially where the management interface is reachable from the internet; the available data does not specify affected version ranges. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-08-18, it was reportedly exploited just five days after disclosure, and EPSS estimates a 45.9% probability of exploitation within 30 days (99th percentile).

Do: Upgrade vCenter Server to the patched release identified in Broadcom's advisory (no specific version ranges are provided in this data) and prioritize any vCenter that is internet-facing, in line with CISA KEV and BOD 26-04 requirements for federal agencies. Until patched, restrict access to the vCenter management interface to trusted networks and verify whether the vCenter Syslog server is enabled. Hunt for compromise indicators, including unexplained remote-access persistence and Babuk ransomware artifacts, given the documented China-nexus exploitation.

9.846% KEV ransomware
  • Broadcom (VMware) vCenter Server
largeApproximately 50,000-100,000 internet-exposed vCenter Server instances, with total deployments (including internal-only) likely in the hundreds of thousands
CVE-2026-59346

NVD description · AI analysis pending
PoC
CVE-2026-59347

NVD description · AI analysis pending