VMware Workstation and Fusion: prioritize the 26H1u1 security update
Broadcom patched two vulnerabilities affecting desktop virtualization. Guest administrator access is a key prerequisite in the described attack paths.

The advisory
Broadcom’s VMSA-2026-0007 addresses CVE-2026-59346, a VMXNET3 integer overflow, and CVE-2026-59347, an HGFS stack buffer overflow. The advisory lists Workstation and Fusion 25H2 and 26H1 as affected, with fixes in 26H1u1 and no workaround.
Understand the prerequisite
Both described attack paths require local administrator privileges inside a guest virtual machine. The VMXNET3 issue can permit code execution on the host; the HGFS issue can execute code as the host’s VMX process. These conditions matter when prioritizing exposure and should remain visible in incident reporting.
AZTCOFW perspective
Include desktop hypervisors in patch ownership, especially machines that run unfamiliar or externally supplied virtual appliances. Separate a guest’s apparent isolation from the trust you place in the software that provides that isolation.
A practical change record should identify the host owner, installed version, update package and post-update validation. Confirm that important development workloads still start and that the new host version is actually installed. Coordinate backups and recovery expectations before the maintenance window.
Follow Broadcom’s current response matrix for the authoritative affected and fixed versions. This brief does not claim these two flaws were exploited in your environment.


