VORANT. Threat Intelligence Sign in Get the full feed

VMware Fusion, Workstation RCE flaws patched

routine vulnerability technology

CERT-FR advisory details two VMware Fusion and Workstation vulnerabilities allowing remote code execution, fixed in version 26H1u1.

CERT-FR issued an advisory covering two vulnerabilities (CVE-2026-59346 and CVE-2026-59347) affecting VMware Fusion and Workstation versions prior to 26H1u1. Both flaws could allow an attacker to achieve remote code execution on affected systems. The advisory references Broadcom's security bulletin (VMSA-2026 #38288, published September 3, 2026) for further technical detail and remediation guidance.

No indication of active exploitation is provided in this advisory. Organizations running affected VMware Fusion or Workstation versions should apply the vendor-supplied patches to reach version 26H1u1 or later as soon as feasible, per the referenced Broadcom bulletin.

Mentioned in this report

Vulnerabilities CVE-2026-59346CVE-2026-59347

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1114

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free